|
À¶ÉÁÖ http://www.lslnet.com 2006Äê8ÔÂ18ÈÕ 15:18
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ΪʲôÎÒµÄsquidÔÚÔËÐÐʱÄÚ´æÒÔ¼°cpuÕ¼Óö¼Ìرð¸ß,¶øÇÒÔËÐÐʱ¼äÔ½³¤,ÄÚ´æÕ¼ÓÃÔ½¶à
Õâ¸öÏÔÏñÕý³£Ã´?¶øÇÒÔڹػúʱ,¹Ø±Õsquid·þÎñÌØ±ðÂý,ÕâÊÇÎªÊ²Ã´ÄØ? |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
¿Í»§Ò»¶àsquid¾ÍÕâÑù¡£
ÅÜsquidµÄ»úÆ÷²»ÒªÉÙÓÚ512MÄڴ棬Íⲿcache×îºÃ²»ÒªÓÃȱʡÅäÖᣠ|
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÓÃaufsÒª±Èufs¸ßЧһЩ£¨¿´ÊÖ²áÖªµÀµÄ£©
aufsÓÃÁËÒì²½´æ´¢¼¼Êõ
ÁíÍ⣬cache_memµÄ´óС¡¢cache_dirµÄÒ»¼¶¡¢¶þ¼¶»º´æÊýÁ¿¡¢cache¸öÊý¶¼ºÜÓн²¾¿ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÄÇÎÒ»ú×ÓÄÚ´æ256µÄ,Íⲿcache¾ÍÊÇ´ÅÅ̽»»»·ÖÇø°É,ÎÒÊÇĬÈϵÄ500¶à,Òª¸ÄµÄ»°ÊDz»ÊÇÒªÖØÐ·ÖÇøÄØ?
cache_mem ÎÒÊÇÉèÖõÄ1g,ÆäÓàĬÈÏ
ÓÐʲôºÃµÄ½â¾ö°ì·¨Ã´? |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
cache_memĬÈϲÅ8M£¬Äã256MµÄÄÚ´æÉèÖóÉ1g£¬²»ÏÖʵÀ²£¡
cache_dirµ¹ÊÇ¿ÉÒÔÉèÖõĴóЩ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÔÎ,ÎÒ˵´íÁË,dirÊÇ1g
ÓÐʲôºÃµÄ½â¾ö°ì·¨Ã´? |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
Ϊʲôsquid½ø³ÌÓÐʱºò˯Ãß,ÓÐʱºòÔËÐÐ,¶øÇÒcpuÕ¼ÓÃÂÊÓÐʱ¸ß´ï98%,¶øÓÐʱֻÓаٷÖÖ®¼¸?¶øÇÒת»»Ìرð¿ì,ºöÈ»¾Í´Ó°Ù·ÖÖ®¼¸¾Íµ½90ÒÔÉÏ? |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
cache_dirÉèÖõÄÔ½´ó£¬´ÅÅÌI/OµÄÆ¿¾±Ô½Ã÷ÏÔ¡£ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
²»ÒªÌ«´óô£¿
cpuÕ¼ÓÃÂÊÄØ£¿´ó¼ÒµÄ¶¼ÊǶàÉÙ£¿ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ºÇºÇ£¬ÓÃSCSIÓ²ÅÌ£¬36G¡Á2£¬×öRAID0£¬¿ÉÄÜÓ²ÅÌÆ¿¾±»áСºÜ¶à |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÔΣ¬ÎÒÃÇûÄÇô¶àÇ®°¡£¬ÓõľÍÊÇ845peµÄ°æ×Ó£¬256µÄÄڴ棬40gµÄÓ²ÅÌ£¬ÔÏÈ»¹Êǿͻ§»úÄØ£¬ÕâÁ½Ììû2¸öСʱµôÒ»´ÎÏߣ¬ÓôÃÆËÀÁË£¬ÕÒ²»³öÎÊÌâ°¡~~~~~~~~ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
´ø¶àÉÙ¸öµã£¿
Èç¹û³¬¹ý50¸ö£¬¾Í²»Òª×ösquidÁË£¬ÕâÑùµÄÅäÖ㬻¹ÊÇ×öNAT±È½ÏºÃ£¬×ösquid·´¶ø»áʹÐÔÄÜϽµ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÔΣ¬´ó¸ç¿´¿´Ìû×ÓÖ÷Ìâ°¡£¬ÎÒÊÇsuqidµÄÎÊÌ⣬ÔõôÌÖÂÛµ½´ÅÅÌÆ¿¾±È¥ÁË
ÎÒÃÇ·þÎñÆ÷»¹ÊÇÒÔǰµÄÀÏ»ú×ÓÄØ£¬ÕâÁ½Ìì»ú×ÓÀϵôÏߣ¬¶¼¿ìÓôÃÆËÀÁË...
×òÌìÍíÉϹØÁ˼¸¸ö·þÎñµ½½ñÌìÔçÉÏÓÖµôÁË~~~ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
¿´ÁËÖ÷Ìâ°¡
ÄãµÄÆ¿¾±ÔÚÄÚ´æºÍÓ²ÅÌÉÏ£¬Èç¹û´øµÄµã¶à£¬Ó²¼þ²»Éý¼¶Ò²Ã»Ï·
Èç¹ûÄã·ÇÒªÓÃ486ÅÜQUAKE3£¬ÎÒҲû°ì·¨ÌæÄã½â¾ö°¡ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÎÒÃÇÒ²¾ÍÊÇ50̨°É...
µ«ÊÇǰ¼¸Ìì¶¼ºÃºÃµÄ£¬Ò»Ö±Ã»³öÎÊÌ⣬×Ô´Ó¸øiptables¼ÓÁ˲ßÂÔ£¬squidÔö´ó´ÅÅÌ»º³åºóû¼¸ÌìÎÊÌâ¾ÍÀ´ÁË£¬Ïȸøiptables¼ÓµÄ²ßÂÔ£¬ÔËÐÐÁ˼¸ÌìûÎÊÌ⣬²ÅÔö´ósquidµÄ»º³å...ǰÁ½Ìì¾Í³öÎÊÌâÁË£¬²é¿´ÏµÍ³ÈÕÖ¾ÊÇsshÓÐÈË´ÓÍâ±ßµÇ½£¨ÏµÍ³°²×°ºÃºóû¹Ø£©£¬¹ØsshºóÎȶ¨ÔËÐÐÁËÊ®¼¸¸öСʱ£¬µ½½ñÌìÔ糿7µãÓÖµô....
ÓôÃÆ°¡£¬×ÜÊÇÕÒ²»³öÎÊÌâ³öÔÚÄÇÀïÁË |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
ÊDz»ÊÇÄãµÄsquid±»ÍâÍøµÄÈËÀûÓÃÁË£¿
Èç¹ûÕÕÄãÕâô˵£¬ÉèÖÃÁËiptablesµÄ͸Ã÷´úÀíºó¾Í³öÏÖÁËÎÊÌ⣬ÄÇÖ»ÄÜ´ÓiptablesµÄÎÊÌâÈ¥¿¼ÂÇ
°ÑÄãµÄiptablesÈ«Ì׽ű¾ÌùÉÏÀ´¿´Ò»Ï |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
squid Ó¦¸Ã»¹¿ÉÒԵġ£ÎÒÕâÀï1000¸öµãÒÔÉÏ£¬µ¥Ì¨PC¾Í¹»ÁË
ÎҵIJο¼ÐÅÏ¢£º·Ç¹¤×÷ʱ¼äûÓÐÁ÷Á¿µÄ
Average HTTP requests per minute since start: 775.5
Median Service Times (seconds) 5 min 60 min:
HTTP Requests (All): 0.04776 0.04776
Cache information for squid:
Request Hit Ratios: 5min: 60.6%, 60min: 54.2%
CPU Usage: 6.67%
CPU Usage, 5 minute avg: 36.13%
CPU Usage, 60 minute avg: 17.93%
ËùÒÔÎÒ¹À¼Æ»¹ÊÇÅäÖÃÎÊÌâ |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
/sbin/iptables -Z
IP="61.185.*.*"
UPLINK="eth1"
ROUTER="yes"
NAT="61.185.*.*"
INTERFACES="lo eth0 eth1"
SERVICES="ssh rsync"
iptables -P INPUT DROP
iptables -A INPUT -i ! ${UPLINK} -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
for x in ${SERVICES}
do
iptables -A INPUT -p tcp --dport ${x} -m state --state NEW -j ACCEPT
done
iptables -A INPUT -p tcp -i ${UPLINK} -j REJECT --reject-with tcp-reset
iptables -A INPUT -p udp -i ${UPLINK} -j REJECT --reject-with icmp-port-unreachable
if [ -e /proc/sys/net/ipv4/tcp_ecn ]
then
echo 0 >; /proc/sys/net/ipv4/tcp_ecn
fi
for x in ${INTERFACES}
do
echo 1 >; /proc/sys/net/ipv4/conf/${x}/rp_filter
done
iptables -t nat -A PREROUTING -p TCP -m tcp --dport 80 -j REDIRECT --to-ports 3128
iptables -t nat -A POSTROUTING -j MASQUERADE
################## CS SERVER Start ################
iptables -t nat -A PREROUTING -p udp -d ${IP} --dport 27015 -j DNAT --to 192.168.1.253:27015
iptables -t nat -A PREROUTING -d ${IP} -p tcp -m tcp --dport 27015 -j DNAT --to-destination 192.168.1.253:27015
################## CS SERVER End
iptablesµÄforwardµÄÁ´ÎÒ»¹Ã»¼Ó£¬Õý×¼±¸¼ÓÄØ£¬¾Í³öÎÊÌâÁË.... |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
--> |
ÇëÎʸ÷λµÄsquidÔËÐÐʱÄÚ´æ¼°cpuÕ¼ÓöàÉÙ,ÎÒÕâ¸öÊDz»ÊÇÓÐÎÊÌâ°¡
platinum ÄãµÄÂÛ̳ÉϵÄÄǸöiptables×ÊÁϲ»´í£¬µÈ»áÈ¥´òÓ¡...
ÄãÓÐqq»òÕßmsnÖ®ÀàµÄô£¿ÄÜÁôÒ»¸ö²»£¿ |
| |