Dear guys,
thank you for answering.
We are using a CentOS 7.2 distribution, x64 architecture.
We use generic e1000 network driver, the Virtual machine runs under VMware 5.5.
We use netfilter on the Firewall machine, another machine, we raised
up the "somaxconn" parameter.
We do not see, right now, any warning about conntrack table full.
We are also trying to resolve from the SAME machine where Bind 9.x
runs, to avoid firewall/nat problems during the testing.
The NIC primary IP address, also from internal, returns delay under heavy load.
If i switch querying an alias IP address - on the same NIC - everything is fast.
Thank you!!
F
2018-06-04 18:04 GMT+02:00 Ict Security :
> Dear guys,
>
> thank you for answering.
> We are using a CentOS 7.2 distribution, x64 architecture.
> We use generic e1000 network driver, the Virtual machine runs under VMware
> 5.5.
>
> We use netfilter on the Firewall machine, another machine, we raised
> up the "somaxconn" parameter.
> We do not see, right now, any warning about conntrack table full.
>
> We are also trying to resolve from the SAME machine where Bind 9.x
> runs, to avoid firewall/nat problems during the testing.
> The NIC primary IP address, also from internal, returns delay under heavy
> load.
> If i switch querying an alias IP address - on the same NIC - everything is
> fast.
>
> Thank you!!
> F
>
> 2018-06-04 17:42 GMT+02:00 Jerry Kemp :
>> Can you please provide some specifics about your setup that is experiencing
>> the problem?
>>
>> HW - Sparc, PPC, Intel x86/x64, ARM ?
>>
>> OS - what OS is the problem occurring on?
>>
>> specific BIND version?
>>
>> anything about the NIC in question, possibly to include mfg && model number,
>> if relevant?
>>
>> Thanks
>>
>>
>>
>> On 04/06/18 07:20, Ict Security wrote:
>>>
>>> Hi guys,
>>>
>>> we are running a Bind 9.x Server, everything is going fine.
>>> Under particular heavy load mometns, with some hundreds of concurrent
>>> queries coming in, sometime Bing stops answering for some seconds or
>>> answer with important delays.
>>>
>>> But, when i try to query the same server/same Bind on a NIC alias IP
>>> during congestion on the main IP, everything is fast!
>>>
>>> I changed some tunings in:
>>> max-connections in /proc
>>> txqueue in network
>>> ipv4_ports
>>>
>>> and i mitigate something.
>>> But it is not completely solved.
>>>
>>> Do you think Bind could have some NIC IP limit?
>>> Some ideas?
>>>
>>> Really thank you!
>>> Francesco
>>> ___
>>
>> ___
>> Please visit https://lists.isc.org/mailman/listinfo/bind-users to
>> unsubscribe from this list
>>
>> bind-users mailing list
>> bind-users@lists.isc.org
>> https://lists.isc.org/mailman/listinfo/bind-users
___
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe
from this list
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users