Re: External Monitoring of https on LB's

2012-08-27 Thread Willy Tarreau
On Tue, Aug 28, 2012 at 02:18:01PM +1000, s...@summerwinter.com wrote: > Hi Willy, > > The only listen-queue patch is for 4.20 - if im running stunnel 4.44 > with the 4.44-xforwarded-for patch, can i use this? As indicated Stefan, recent versions already use SOMAXCONN which is 128, so it's much

Re: External Monitoring of https on LB's

2012-08-27 Thread syd
Hi Willy, The only listen-queue patch is for 4.20 - if im running stunnel 4.44 with the 4.44-xforwarded-for patch, can i use this? Quoting Willy Tarreau : On Mon, Aug 27, 2012 at 04:04:52PM +1000, s...@summerwinter.com wrote: Hi Willy & BAptiste, I've been running stunnel-4.44 already p

Re: External Monitoring of https on LB's

2012-08-27 Thread Willy Tarreau
Hi Stefan, On Mon, Aug 27, 2012 at 11:41:53AM +0200, Craig Craig wrote: > Hi, > > a patch is already upstream. I put some effort into getting patches upstream: > > http://groups.google.com/group/mailing.unix.stunnel-users/tree/browse_frm/month/2011-02/a1956cc49beaf689?rnum=11&_done=%2Fgroup%2Fma

Re: External Monitoring of https on LB's

2012-08-27 Thread Craig Craig
Hi, a patch is already upstream. I put some effort into getting patches upstream: http://groups.google.com/group/mailing.unix.stunnel-users/tree/browse_frm/month/2011-02/a1956cc49beaf689?rnum=11&_done=%2Fgroup%2Fmailing.unix.stunnel-users%2Fbrowse_frm%2Fmonth%2F2011-02%3Ffwc%3D1%26#doc_2d06864707

Re: External Monitoring of https on LB's

2012-08-27 Thread Willy Tarreau
On Mon, Aug 27, 2012 at 04:04:52PM +1000, s...@summerwinter.com wrote: > Hi Willy & BAptiste, > > I've been running stunnel-4.44 already patched with > xforwarded-for-diff from that link. > > How should I set the listenqueue param? via stunnel.conf? yes, but once you've applied the listen-queu

Re: External Monitoring of https on LB's

2012-08-26 Thread syd
Hi Willy & BAptiste, I've been running stunnel-4.44 already patched with xforwarded-for-diff from that link. How should I set the listenqueue param? via stunnel.conf? Out of the detailed logs available from HyperSpin, they have 20 or so servers which connect to test at random. The same 3 s

Re: External Monitoring of https on LB's

2012-08-26 Thread Willy Tarreau
Hi, On Mon, Aug 27, 2012 at 09:11:43AM +1000, s...@summerwinter.com wrote: > Hi there, > > Forgive me if this is the wrong place for advice, but I figure a lot > of people here must use a similar setup. > > I've got 2 LB's setup with haproxy, heartbeat & stunnel. Http & https > is working co

Re: External Monitoring of https on LB's

2012-08-26 Thread Baptiste
> === > [admin@sg ~]$ curl https:// > curl: (35) Unknown SSL protocol error in connection to :443 > Hi Syd, I have no idea, but a tcpdump during the error may help. Have you enabled verbose logging in Stunnel and tcplogs in HAProxy? Could be useful too

External Monitoring of https on LB's

2012-08-26 Thread syd
Hi there, Forgive me if this is the wrong place for advice, but I figure a lot of people here must use a similar setup. I've got 2 LB's setup with haproxy, heartbeat & stunnel. Http & https is working correctly. I am using HyperSpin.com for external monitoring to receive alerts based on