Tracking Forums, Newsgroups, Maling Lists
Home Scripts Tutorials Tracker Forums
  Advanced Search
  HOME    TRACKER    Web Hosting


Advertisements:




SuperbHosting.net & Arvixe.com have generously sponsored dedicated servers and web hosting to ensure a reliable and scalable dedicated hosting solution for BigResource.com.







Virtualization Vmware And Dos & Syn Attack


How will VMware ESX Servers handle a dos, ddos or syn attacks? Will it compleatly crash all VM running on the server just becouse one VM and its ip interface is attacked and make file systems monted on a san or nas to be corrupt becouse of the traffic on the local network will be downgraded becouse of all packets that passes to the VM:?

Does vmware have some protection tools for this kind o attacks or does this kind of virutalization only work in a an lan that is protected from Internet?

Will 2 dedicated nic solve this?


View Complete Thread with Replies

Sponsored Links:

Related Forum Messages:
Virtualization Solution? VMware, Virtuozzo, Xen..?
I'm running a dedicated server and the main site on the server relies on Windows OS. The site is not fully utilizing the potential of the dedicated server, so I'd like to put some of my other sites on the same server and eliminate the other (shared) hosting I've been using.

Here's the catch... For the other sites, I'd like to run WHM/Cpanel which requires Linux.

If I understand correctly, this leaves me with having to decide on a virtualization solution, which I know nothing about. Some options I have been given are VMware, Virtuozzo, and Xen.

Would you suggest one of these or a different solution entirely?

View Replies!   View Related
SYN Attack
i found my site load slowly, the cpu load is good. I run this command
[root@host ~]# netstat -nap |grep SYN |wc -l
526

It's seem my server is having problem with SYN attack. Is there anyway to protect it ?

I'm running apache 2.

View Replies!   View Related
SYN Attack
i am just having one issue in one of my highly visited website hangibar.com, its being hosted in softlayer, we are facing synattack too much in this website.

the solution which microsoft given in their website related with tcp/ip registry entry but thing is same , some where and some connections become increases too much over tcp/ip. due to that reason website become very sticky and it stop functioning the execution of sql process, during this issue i have to restart the server to establish a fresh connection.

View Replies!   View Related
Syn Attack
im getting a syn attack and my vps getting overloaded what im doing is banning ip's that gets most connections

after banning server get normal but if there anyway to stop this post method

View Replies!   View Related
Virtualization - Enterprise Installs? VMWare, Xen, Virtual Iron?
A company i am working with is looking to install a VMWare setup comprising of something like this :

6x Dual Proc Quad Core Nodes with 16GB RAM
2x Clustered iSCSN SAN Nodes

I am intending on purchasing the full suite including DRS/HA/VMotion.

Now this is all well and good but the software pricing is absolutely horrendous! So my question to you chaps is :

Is anyone using the latest Virtual Iron or Xen Enterprise in a high end environment?

Obviously VMWare is the market leader, the big boys are using it and its something you can bank on. (literally! HSBC use it ALOT!)

Is it even worth looking at VI/Xen for something like this? The cost would be like a quarter of the total cost of a VMWare license.

View Replies!   View Related
SYN Flood Attack
We are currently experiencing an SYN Flood attack on our primary production server and are looking for some help in resolving the issue.

Running:
Novell SUSE Linux Enterprise Server 10.2-64
SuperMicro X7DBR-E Intel Xeon QuadCore DualProc SATA [2Proc]
Processor Intel Xeon-Clovertown 5320L-QuadCore [1.86GHz]
8GB Memory
@ Softlayer DC in Texas.

Need help within the next hour or two. Please ask any necessary follow up questions and how you might go about resolving the issue (i.e. SYN Cookies, etc.)

View Replies!   View Related
SYN Flood Attack
someone decided to attack my webserver and I can't figure out how to block it.

tcp 0 0 localhost:80 207.44.129.88:2138 SYN_RECV
tcp 0 0 localhost:80 207.44.129.88:2243 SYN_RECV
tcp 0 0 localhost:80 213.66.121.211:63372 SYN_RECV

It's literally thousands of those requests overloading apache. The server is fine, the load average is like .8. But none of the website are loading.

We're hosting with ThePlanet, and they're doing a great job at blocking a huge portion of the attack. But we're still getting hit pretty hard. I've got APF installed, and 3 or 4 anti-dos scripts.

Every once in a while a page will load for the websites, I think we've got just under 50 legit connections.

View Replies!   View Related
I'm Under A Syn Flooding Attack From Single IP
My website has been under a constant Syn Flood DoS attack for the past few days. However, the attack originates from a single IP address that changes every few hours (Possibly a syn flood script with IP spoofing capabilities).

The Syn Flood attack isn't creating any spike whatsoever in my usage graphs, however, its still rather annoying. What firewall should I use to combat the DoS attack?

View Replies!   View Related
Inbound SYN Flood Attack
my server under attack with syn flood and i attach the active connection during attack

View Replies!   View Related
Is This A DOS Attack?
Quote:




Mar 10 20:17:55 host kernel: printk: 102 messages suppressed.
Mar 10 20:17:56 host kernel: printk: 3 messages suppressed.
Mar 10 20:18:01 host kernel: printk: 98 messages suppressed.
Mar 10 20:18:35 host kernel: printk: 34 messages suppressed.
Mar 10 20:18:51 host kernel: printk: 189 messages suppressed.
Mar 10 20:18:56 host kernel: printk: 195 messages suppressed.
Mar 10 20:19:02 host kernel: printk: 249 messages suppressed.
Mar 10 20:19:06 host kernel: printk: 36 messages suppressed.
Mar 10 20:19:21 host kernel: printk: 3 messages suppressed.
Mar 10 20:19:26 host kernel: printk: 342 messages suppressed.
Mar 10 20:19:31 host kernel: printk: 509 messages suppressed.
Mar 10 20:19:47 host kernel: printk: 54 messages suppressed.
Mar 10 20:19:51 host kernel: printk: 421 messages suppressed.
Mar 10 20:19:56 host kernel: printk: 542 messages suppressed.
Mar 10 20:20:01 host kernel: printk: 785 messages suppressed.
Mar 10 20:20:16 host kernel: printk: 340 messages suppressed.
Mar 10 20:20:21 host kernel: printk: 337 messages suppressed.
Mar 10 20:20:26 host kernel: printk: 430 messages suppressed.




Or is this something else? It's been going on for about 40 minutes. I seen my load jump to 20, to 100 and back and fourth

View Replies!   View Related
Dos Attack
Am Really suffering here for ddos attack ( apache - pop3 ) every week my server under attack am using APF but now am really wanna get red from it am looking for a powerfull firewall I do not know if CSF Could stop this attack like limiting receiving SYN from an ip or any other policy another thing . i have get this rules from forums but am really weak at iptables rules so can any one help my if these rules useful or not . against Dos attack:

iptables -t nat -N syn-flood
iptables -t nat -A syn-flood -m limit --limit 12/s --limit-burst 24 -j RETURN
iptables -t nat -A syn-flood -j DROP
iptables -t nat -A PREROUTING -i eth0 -d (dest ip) -p tcp --syn -j syn-flood

View Replies!   View Related
DOS Attack And APF
My server is under dos attack (http) , I have installed APF firewall and ddos deflate. I configure them to work together.

now if any IP with more than 100 connections is black listed by dos deflate, I can see it in apf's deny_hosts.rules file.

everything seems correct, but my server still very slow.

the ip which is causing that has more than 1000 request and is blacklisted.

View Replies!   View Related
Where To Report DoS Attack
I'm hosting my website on a shared hosting, and recently the ip 87.255.1.42 began sending DoS attacks to my website - there are constantly being sent queries to the starting page of my website, more than 400,000 queries/day.

It's not doing any significant damage but overloads the server every day, and I would like to know how to report this attack to any authority who can stop the attack.

I queried the RIPE database
db.ripe.net/whois?form_type=simple

View Replies!   View Related
Dos Attack Hardware
PHP Code:

---------------------------- Local Attack Statistics --------------------------
  ICMP Drop Count    ICMP Block Count    SYN Drop Count    SYN Block Count
  ---------------    ----------------    --------------    ---------------
             2538                   8          66382803                383
  --------------------------- Transit Attack Statistics -------------------------
  Port   ICMP Drop Count    ICMP Block Count    SYN Drop Count    SYN Block Count
  -----  ---------------    ----------------    --------------    --------------- 

What firewall does that look like? my provider is charging me too much money for this managed firewall to projtect against DOS attack... if i can afford the equipment myself, why would I need to pay for it right?

View Replies!   View Related
Resolving A DoS Attack
We've just been told by our data centre that our server that we use to host our web design clients has been disconnected due to massive volumes of traffic from or to the server.

They said I will need to log into a KMV/IP in order to investigate.

I have no idea what I am doing and was wondering if there are any users out there that could give me some pointers in finding what is causing this DoS attack?

View Replies!   View Related
Apache DoS Global Attack
I have just saw on leaseweb noc site that there has been a public release of a Apache DoS tool and all All versions of Apache are vulnerable.

So can anyone confirm this and give some possible solution or advices? ....

View Replies!   View Related
Check Server For Dos Attack
How can check server for dos/ddos/syn attack?

Because my server load is high, perfromance is low, but i dont have any high process.

View Replies!   View Related
Millions Of Hits + DOS Attack
I have a website that offers web stats. It receives like 30 million hits per day (legitimate) in addition to a large number of invalid URL requests and DOS attacks that max at 50MB. I currently have a server at liquidweb who, after bearing too much with me, informed me that I might have to move away some day because the attacks are affecting their network. I have been with them for 4 years now.

We tried using a normal firewall but it couldn't handle the normal requests. I don't have a budget to afford an expensive one. Firewall tweaking is not easy because of the large number of legitimate requests.

So, my questions are:

1. What should I do? Is there a known, affordable firewall that can help (or any other setting)?

2. Which hosting company will take me and manage to make things work without getting their network affected?

View Replies!   View Related
UDP D/DoS Attack - Best Prevention
I would like to know what are the best ways in preventing a UDP D/DoS Attack. DDoS-Deflate and most programs like that are just for TCP connections, and most of the time only for port 80. What is the best option out there for protection (linux wise) for UDP attacks. I was using shorewall before but it did not do so well so I just switched now to CSF [url] with WebMin and seems to be working ok. Even though thoes are both firewalls, they seem to have some protection against UDP Attacks. Please note this is a server that just hosts some game servers, no webhosting. What would be my best option here?

View Replies!   View Related
DOS Attack, Datacenter Not Helping
One of My server's main ip address has been null routed by my data center since last 8+ hours. They say I am getting DDOS attack on my server. However, I have asked them several times to tell me more details about what is the size of attack but they do not response in proper way. Technician just say I am getting DOS attack and they can not put my ip back online as its effecting other servers on network.

I seen MRTG graphs provided by datacenter and it appears the incoming traffic size was 6-7mbps (MAX). Is that big size?

I am trying to understand how null routing my ip will help users on network and why they are not providing me any details except few ip addresses.

How much time, I must wait. I am already offline since last 8+ hours and they are asking me to wait 6 more hours before they will put my ip online to see if attack is stopped. If not then again 6+ hour downtime window.

Can't they do anything about it? What else should I be asking them to get know more about this attack so that I can ask these questions to my next provider to know if they can handle such situation?

View Replies!   View Related
20Mbit DoS Attack With UDP
I have a problem since two days. I am facing a DoS attack on one of my IP's with 20Mbit of UDP Packets.

These are the packets I receive:

Code:
16:19:26.949003 IP (tos 0x0, ttl 49, id 14236, offset 0, flags [DF], proto: UDP (17), length: 29) 222.90.73.53.33713 > foo.com.www: [udp sum ok] UDP, length 1

My provider says they can't do anything. The only thing they could do is shut down my IP. Which is not really helpful. I have no idea what to do or what else I could analyze.

It would be very interesting if the IP is being attacked or one of the sites I host.

I have already over 300GB traffic since yesterday because of this.

View Replies!   View Related
Slow Server - DoS Attack
My server (Xeon 3.0Ghz) went down for no reason yesterday and ever since it was rebooted (and I've rebooted a couple of times since then), pages load extremely slowly or just timeout. Server load is constantly hovering around 1 and top stats indicate that the server's resources are not under heavy load, which is contrary to the usual pattern during peak times.

I've checked netstat and I notice a lot of SYN_RECV. Could this be a DoS attack? If so, what steps do I take to stop it?

View Replies!   View Related
Ddos / DoS Attack, Won't Stop. Server Is Down
My server was hit with flood recently, to the point where I was unable to log in via SSH. Running 'netstat' command showed I was getting flooded with thousands of http requests from China/Saudi Arabia/Korea. I installed APF firewall and added those countries to deny list.

Next day I was hit from Russia and Romania and some others. By reading some posts on this site, on top of APF, I have also installed Dos Deflate. It was working for couple of hours, but then it stopped working. I could not even log in via SSH. My provider told me that APF was using all of the "conntrack" connections. I have increased conntrack connections to 130,000 (I have 4 Gigs of RAM on my server). Is that possible? (I have about 300 IP ranges in my APF deny list).

Next day, I was got hit by different attack: there was 11 Mbps of malicious traffic on average sent to my server. My provider put me behind firewall to mitigate against that kind of attack.

Currently, I am both behind the hardware firewall and I have APF and Dos Deflate running. However my server is not accessible.

When I request, I can log in for couple of minutes, but then I get kicked out.

View Replies!   View Related
Using IPSec Policies To Help Prevent DoS Attack
Is it possible to use IP Security policies in Windows Server 2003 to help prevent types of DoS attacks? Today my server was attacked by a single attacker who merely connected and disconnected on open ports at an incredibly fast rate. This was enough to eat the cycles of the server processes effectively creating a DoS attack. I was hoping IPSec could help prevent this, but I'm open to use any other software as well.

View Replies!   View Related
Someone Hacked My Server And Launched A DoS Attack On Someone Else.
OS: Centos 4

Someone managed to get into my server and launched a DoS attack on someone else machine.

How do I find out the person who did this?

How do I find out how the person got in in the first place?

How do I make sure that it cannot happen again using the same method?

View Replies!   View Related
DOS Attack Over Apache, Full Of READING Connections
As you can see my apache is full of Reading connections..... they are filling up my server dening legitimate users to browse trought the websites hosted there... I think this is what is happening to me:
http://mail-archives.apache.org/mod_...l.gmail.com%3E

Im using apache 1.3.3.7 on RHES 3 with latest patches and kernel.

930 requests currently being processed, 6 idle servers
RRRRRRRRWRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRWRRRRRRRRRRRRR
RRRRRRRRRWRRRWRRRRRRRRRRRRRRRWRRRRRRRRRRRRRRRRRRRWRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR_RRRRRRRRRRRRR_RRRRRRR
RRRRRRRRRRRRRRRRRRRRRRWRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
R_WRRRRRRRRRRRRRRRRRRRRWWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRWRRRRRRR
RRRRRRRRRRRRRWRR_RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR_
RRRRRRRRRRRRRRRRRRRRRRWRRRRRRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRR_RRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRWRRRRR
RRRRRRRRRRWRRRRRRRRRRRRRRRRRRRRRRRRRR.RRR.......................

1-044940/40/40R 0.33340.00.060.06 ??..reading..
2-044950/55/55R 0.47330.00.110.11 ??..reading..
3-044960/35/35R 0.31330.00.050.05 ??..reading..
4-044970/38/38R 0.13210.00.090.09 ??..reading..
5-045410/40/40R 0.16360.00.130.13 ??..reading..
6-046190/28/28R 0.12110.00.030.03 ??..reading..
7-046220/34/34R 0.35320.00.100.10 ??..reading..
8-051640/34/34R 0.135100.00.300.30 ??..reading..

Also, here is the top output of the top command:

top - 12:46:21 up 10 min, 1 user, load average: 1.40, 2.03, 1.06
Tasks: 1063 total, 2 running, 1060 sleeping, 0 stopped, 1 zombie
Cpu(s): 4.9% us, 1.6% sy, 0.0% ni, 93.1% id, 0.3% wa, 0.0% hi, 0.0% si
Mem: 2073516k total, 2001984k used, 71532k free, 42384k buffers
Swap: 2048276k total, 0k used, 2048276k free, 178096k cached

Server seems to be fine, but total tasks are always between 1060 and 1124... thats very rare too..

how to avoid this attack?

View Replies!   View Related
Incomign DOS Attack They Black Hole My IP And All Sites Are Down
I just got email from the company with which I co locate my servers (one of the resellers in MPT). The email said:

"We have detected a deny of service attack on one of your IP's
69.90.xxx.xxx. The attack was approximately 200Kpps and 120Mbps. The
IP has been null routed and will be in place for 24 hours."

Now all my sites hosted on that IP are down.

Is this the way the co location companies and their upstream providers deal with DOS attacks?

Its going to harm me a lot if I have to wait for 24 hours for the
services to work.

View Replies!   View Related
Script To Stop Syn Flooding - Syn Deflate
I made a thread about this in programming as I was trying to figure it out but I ended up tweaking dos deflate a lil and got it working. Tried and tested as well during low bandwidth syn flood. Keep in mind if you are having massive syn attacks then most of it will have to be filtered on the network level. I have filtering from staminus on my server, this is just for the low bandwidth stuff that gets through.

Syn-deflate is just a name I came up with as it is based on dos-deflate, only a few changed features. I dont know how medialayer would feel about me modifying their script this way I know they got lisence and copywrite on it. Guess I will talk to them about that before any official release.

especially about the csf version.

So I always have used some dos deflate features to monitor dos in my servers, just the netstat command. This one:

Code:
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
Today, got a syn flood coming through, low bandwidth, etc. Each ip connecting under the tracking limit for csf. So I tweaked the netstat command a lil bit and I was able to see what ips were sending syn and how many times.

Like this:

Code:
netstat -ntu | grep SYN_RECV | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr
So I figured it would be very handy to ban ips sending over so many SYN_RECV connections at once. So I took dos deflate and tweaked it a lil. Made this to work with csf. Only problem on csf is there is no unban command, only whitelist so I just had it do csf -d again on the unban command, This would give an error and would not unban the ip but you really dont need to unban it so soon.

With apf it works perfectly on unbanning. Works just like dos deflate but bans syn flooders not connection flooders. You could even use this along with dos deflate. I am using it along side of csf and the connection tracking feature no problem.

I plan on releasing some what of an official version too along with some other tools to monitor and stop dos. So whoever is interested or can offer some advice let me know.

For those who wanna give it a try:

For the CSF version:

To install:

Code:
wget[url]
To uninstall

Code:
wget [url]
For the Apf and Generic Iptables version:

To install

Code:
wget [url]
To uninstall

Code:
wget [url]
uninstall.synd ; ./uninstall.synd

I didnt get to try the apf version out much but have used the csf version all day with no issues

Note to makers of dos-deflate: Im not too keen on all this licensing stuff or what I am supposed to do when I modify someone else script so let me know what I need to do to keep from making anyone mad.

View Replies!   View Related
Hardware Level Virtualization Or Software Level Virtualization
Which virtualization technology is better? Hardware level or software level? My friend suggested me to go for software level virtualization. However, I am still concerned about the technology as to which I should choose?

View Replies!   View Related
Hardware Level Virtualization Or Software Level Virtualization ...?
Which virtualization technology is better? Hardware level or software level? My friend suggested me to go for software level virtualization. However, I am still concerned about the technology as to which I should choose?

View Replies!   View Related
Syn Flood
I've been getting a syn flood for the last week or so.

I've pretty much tried everything I could online but have been unsuccessful in stopping them.

I talked to the data center techs and they basically can't put a stop to it either.

Here's a very small portion of my netstat

tcp 0 0 xxx.xxx.xxx.xxx:80 86.50.121.144:8540 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 41.100.16.152:7824 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 52.53.22.7:3146 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 77.217.49.124:1659 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 75.162.93.151:3230 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 113.85.63.249:1656 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 15.253.35.29:8849 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 24.56.59.180:6911 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 33.185.99.83:1917 SYN_RECV -
tcp 0 0 xxx.xxx.xxx.xxx:80 103.5.8.249:4782 SYN_RECV -

root@xxx [/]# netstat -nap |grep SYN |wc -l
2008

The IP's change often and it's not possible to narrow it down.

So far the things I have done;

syn cookies enabled

reduced time out
echo "1" > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_syn_recv

increased
echo "150000" > /proc/sys/net/ipv4/ip_conntrack_max

installed apf but it slowed down the server to a crawl which made my clients really unhappy so had to remove it.

The bandwidth is constantly staying at 30Mbps with slight bumps here and there but every day around 7pm it drops completely to normal levels and the flood stops. It starts back up around 7 in the morning.

View Replies!   View Related
SYN Flooding
Well I've tried Staminus and Awknet and they both just seem to rate-limit if I get like 300MBIT SYN, is there any provider that won't just rate-limit but will actually filter the attack for around $200/mo?

View Replies!   View Related
SYN Attackt
i have big syn attackts i cant stop. who can help me ? i need a good server administrator.

my msn: vip@akif.org

View Replies!   View Related
Virtualization Technology
Aspnix.com has offered Virtualization Technology on their dedicated servers - do you know what it means?

View Replies!   View Related
Virtualization Platform
In another thread somebody had mentioned something about Citrix Xenserver utilizing shared iSCSI storage with multiple hardware nodes. I think this is a very intriguing concept, but is there anything open source or less expensive that you have used to accomplish similar resource virtualization?

Whether citrix or not, describe your setup!

View Replies!   View Related
Which Virtualization For Desktop
This is a little bit Offtopic here but maybe it's okay to ask my question.

For my GUI software development i need a virtual server solution. It must run WinXP, WinVista, LinuxI386, LinuxAMD64, FreeBSDI386, FreeBSDAMD64 and Solaris.

I'm currently running VMWare with all this systems. But their KVM tools are very instable - especially when waking up from hibernate etc. They eat the key/mouse focus and the only way to get any reaction is often a hard shutdown.

How good are the other Virtualization Kits? I heared that FreeBSD does not work on VirtualBox? I'm especially interested in Xen but i'm not sure if this is good for Desktop use. Seems that it is promoted almost exclusively as a server solution.

View Replies!   View Related
Apache X Virtualization
We usually find some constrains using Apache/cpanel (1.3.41). Basically, we serve simple php codes and few images.

We usually setup our server to use lighttpd for static content and apache for dynamic content. Ok, due to some complex requirements on mod_rewrite we use that setup.

But frequently we see our apache reaches it limit and slow down with 0 idle servers. Specially as we have about 270 requests/per second on apache. Our load is low, barely passes 1,2 of load for small periods, our memory ok, our I/O is fine.

But we almost always reaches the 0 idle servers. Until now, our best config was:

Timeout between 60-120
KeepAlive Off
MaxKeepAliveRequests 1000
KeepAliveTimeout 15
MinSpareServers 50
MaxSpareServers 200
StartServers 50
MaxClients 256
MaxRequestsPerChild 80

As we clearly see that our server is under usage, I was wondering if it's a limitation on Apache or if I put virtualization on my server and run two apache webservers as cluster I would get better results.

So what do you think about guys? It's a matter of optimization (what could I do better for this httpd.conf setup?) ? Or cluster with virtualization would deliver what I'm looking for.

View Replies!   View Related
What Virtualization Software Do You Like
What Virtualization Software Do You Like?

Please vote among Virtuozzo, Xen, OpenVZ.

View Replies!   View Related
Which Virtualization Technology
I have tried to search but couldn't find the information I was looking for. We are starting to offer VPS and considering MS Virtual Server and vmWare. vmWare seems rock solid and feature rich. Which virtualization technology you are using? Is vmWare a good platform for vps for hosting industry?

View Replies!   View Related
How Can I Best Work With A Syn Flood?
How can I best work with a syn flood? I've tried the apf, deflate-ddos etc.... and don't work. Even tried litespeed etc but doesn't work against a 90mbps attack.

If I get a few servers, how would I have it setup to best defend?

View Replies!   View Related
Syn Flood Protection
one of my server were hit by massive ddos syn atack. target was port 80-apache

i am running centos 5 in xen vps iptables were strong with syn filtering and limit
but...what can do?

View Replies!   View Related
Does Keepalive Off Help In Syn Flood
Does keepalive off help in syn flood?

View Replies!   View Related
Anyone Know These: SYN Hosting Or TmzHosting
Anyone know these: SYN Hosting or TmzHosting

How do these two compare with shared hosting?

View Replies!   View Related
SYN Flood .. No Way To Stop It ?
One of the servers have 1 account on, but seems like its extremely attacked. I cannot SSH and many packet loss. so I asked softlayer and they access it and said its a SYN Flood as from the /var/log/messages (I cannot see it as the server is not accessable) they put the main public ip under Cisco guard but still didn't help. when I asked for any solution, unfortunaly I were told there isn't and have to wait the attackers to stop as it comes from MANY addresses that iptables even won't help.

Isn't there any solution (software-hardware) to stop that ?

View Replies!   View Related
Possible SYN Flooding On Port 80
my new server performs strange
I checked /var/log/messages
there are full of these messages

possible SYN flooding on port 80. Sending cookies.
kernel: printk: 84 messages suppressed.
kernel: nf_conntrack: table full, dropping packet.

my site is a huge site, thousands of ppl online
I think i am not been attacked, but kernel think so.
How to resovle this problem.
How can I stop netfilter from kernel

kernel:@2.6.22.1-32.fc6
2 xoen 2.8g, 2gb ram, 73gb scsi hd

View Replies!   View Related
Virtualization Web Panel
tell me which web panel recommend for xen virtuo.?

i need frontend of panel.

View Replies!   View Related
To Do Virtualization Inside VPS
I have this nice vps, but its on linux, and I always wanted to run windows apps on the vps, because of the nice configuration. I already tried wine, but most of my windows apps don't work, cuz they require .net framework to run.

I tried to instal vmware server and virtualbox, but both of them complain about a kernel problem, they are unable to locate my kernel source, so they can't run.

I am linux newbie, and i am running on a centos 5 operating system.

Some people say its impossible to run virtualization 'inside' virtualization, but i already read some people that say its possible.

View Replies!   View Related
Microsoft Licensing For Virtualization
Microsoft said this about Microsoft Licensing for Virtualization

Windows Server 2008 Datacenter
Run any number of software instances in physical and virtual operating system environments on a server.

Now,I have some questions:

1)Is this method of licensing just for hyper-v or we can use it on vmware ESXi or Xen?

2)How we can use Microsoft Volume Licensing on Vmware ESXi and Xen?

3)What is the best solution for windows virtualization?(vmware esxi or hyper-v or xen)

4)what is difference between xen and xenserver?

5)which control panels we can use for hyper-v,vmware ESXi and xenserver?

View Replies!   View Related
Virtual Iron Virtualization
Basically I need to virtualize a single new dell server. One virtual server needs to run windows 2003 server standard and Microsoft SQL 2005. The other virtual server will run CentOS Linux with a perl and PostgreSQL application.

The dell server is going to have two quad core xeon processors (8 cores total), 8gigs of ram, and two 15,000rpm SAS drives.

I came across Virutal Iron which is free for the single server instance and seems like it will do the job well. Has anybody used it? What is performance like? Seems to run a Java backend so wondering about the performance there.

Any other recommendations? I looked at VMware but the cost is so high, and probably more then I need, since I only need to virtualize a single server.

View Replies!   View Related
Virtualization WIN 2008
I have a machine with 2*Xeon 2.66, 16GB Ram, 146GB Raid 1, 292GB Raid 10.

This machine will be used to run Mysql (32bits or 64bits) and MDaemon (32bits only).

I have 2 options to choose and I'm not pretty sure which is better.

a) Win 2008 32bits Enterprize using PAE for ram support and running Mdaemon 32 and Mysql 32.

b) Win 2008 64bits standard having virtualized a win 2008 64 bits for Mysql 64 and a win 2008 32 bits for MDaemon 32.

View Replies!   View Related
Which Virtualization Guest Operating System
For all of you who are ordering / have ordered VPS systems, what do you think about having Windows vs Linux available from your provider?

View Replies!   View Related
Just Bough A New Server - Virtualization / CPanel
Just bought

PU: 2 x Intel Xeon E5410 Quad-Core 2.33GHz, 12MB Cache, 1333MHz FSB, 45nm Hi-k
RAM: 12GB (6 x 2GB) DDR2-667 Registered ECC - Interleaved
NIC: Intel 82573V & 82573L Gigabit Ethernet Controllers - Integrated

Hot-Swap Drive - 1: 150GB Western Digital Raptor (1.5Gb/s,10Krpm,16MB Cache,NCQ) SATA
Hot-Swap Drive - 2: 500GB Western Digital RE2-GP (3.0Gb/s, Variable Speed, 16MB Cache) SATA
Optical Drive: Low-Profile 8x DVD +/- RW Drive
Power Supply: 520W Power Supply with PFC - 87% Maximum Efficiency
Rail Kit: 2-Piece Ball-Bearing Rail Kit
OS: CentOS 5 - 64-bit - Preload, No Media

I want to use it for running 2 Vbulletin forums, 1 big blog and Image Hosting

do you think its better for me to put as Virtualization and run individually OR just install Cpanel and Put everything together at once?

View Replies!   View Related
Xen Para Or Full Virtualization
what the hosts are using for xen virtualization. Para or Full virtualization and why?

View Replies!   View Related
Copyright © 2005-08 www.BigResource.com, All rights reserved