Monitor connections on shibboleth

Cantor, Scott cantor.2 at osu.edu
Tue Jan 24 14:35:43 EST 2017


> Seems like you never sleep, always the first one to respond. I just just
> talking about tcp connections. Last semester we only had one shibboleth box
> with no load balancer, and during the 1st week of school my server was
> getting hammered by students trying to authenticate while trying to sign up
> for classes.

Unwindowed? OSU can handle our full login load on one VM with a bit of sweating, and a physical box wouldn't even notice. Just for comparison. 65,000 students, 150,000 total accounts.

Generally an SSO system getting hammered implies some kind of pretty unusual application load.

> I'm hopping with this new load balancer and a second shibboleth
> box that the load should be evenly distributed between the two. My
> curiosity wanted to know if others might have a better way to monitor tcp
> connections, and suggestions on how better with shibboleth monitoring. That's all I was
> curious about right now.

No experience with network monitoring but the load balancer could probably feed that sort of information. Alternatively maybe measure counts of audit log records. Not exactly connections but illustrates the comparative traffic handled on each box.

-- Scott



More information about the users mailing list