sk182063 - SmartConsole slowness when adding applications to rules
SmartConsole slowness when adding applications to rules
Product: Multi-Domain Security Management, Security Management
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2024-07-01
Symptoms
- SmartConsole slowness when adding applications to rules in the Access Control policy.
- The
show objectsAPI command times out when there is a large number of applications in the database. - If the Management Server had many application updates, the APPI domain is large in the postgres database.
Cause
The Management Server stores all revisions of each Application Control and URL Filtering update. To prevent it from taking all of the disk space, APPI purge runs and cleans old unused revisions in the database.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 152
If you choose not to upgrade, use APPI purge which removes old and unused APPI versions in the database.
In a High Availability environment, the APPI purge runs on the active Management Server.
In a Multi-Domain environment, the APPI purge only runs on the Multi-Domain Server with the active Global domain.
In a multi-site environment, the APPI purge only runs on the Multi-Domain Server with the active Global domain and it relays to check the assigned APPI versions for each domain in order not to purge these versions.
To run the APPI purge automatically:
By default, the APPI purge runs every Sunday at 1am.
To change the schedule, configure the days and hours on which it runs.
For the day: 1=Sunday, 2=Monday, 3=Tuesday, 4=Wednesday, 5=Thursday, 6=Friday, 7=Saturday
The hour must be in the 24-hour time format:
Example for configuring a purge that runs every Tuesday at 3pm:
$MDS_FWDIR/scripts/reload_env_vars.sh -e "APPI_PURGE_DAYS=3;APPI_PURGE_HOUR=15:00:00"
$MDS_FWDIR/scripts/override_server_setting.sh -e APPI_PURGE_DAYS 3
$MDS_FWDIR/scripts/override_server_setting.sh -e APPI_PURGE_HOUR 15:00:00
How to run the APPI purge manually:
$MDS_FWDIR/scripts/reload_env_vars.sh -e RUN_APPI_PURGE=1
To disable the APPI purge:
$MDS_FWDIR/scripts/reload_env_vars.sh -e DISABLE_APPI_PURGE=1
$MDS_FWDIR/scripts/override_server_setting.sh -e DISABLE_APPI_PURGE 1
To debug the APPI purge:
$MDS_FWDIR/scripts/cpm_debug.sh -c AppiDomainPurgeManager,CpmRelaySvcImpl,RevisionsSvcImpl -s debug
You can then replicate the issue by running the APPI purge manually (see above):
Open $MDS_FWDIR/log/cpm.elg and review the lines which include AppiDomainPurgeManager.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.