Hi,
We're running a squid proxy (version squid-2.5.STABLE3-6.3E) on RHEL3
(2.4.21-37.EL) on a HP DL360.
average load is 1.5
actually, it's 2 proxy servers loadbalanced by our dns server.
Since a few weeks now, we're plagued by long network delays whilst surfing.
they last for about 5 minutes and the problem disappears automatically
without any warnings or info in the logfiles. (the problem occurs approx.
2times per day)
To determine if the cause was squid or not, i ran a script that issued wget
commands that bypassed squid, and the problem seems to be unrelated to
squid: wget also had the same issues.
I was lucky to be on the system just when the problem occurred, and I
noticed that netstat -an showed a lot of connections in SYN_SENT state, even
thoug at that time, there were no network problems.
So how can I check this out further ? It could either be the firewall I
guess (checkpoint), or smartdefense (checkpoint module to watch for
unhealthy network traffic), or perhaps it could be a problem with the linux
kernel ???
average number of active network connections is 600 per server.
any ideas how to debug this further ?
thanks,
Tom.
|