Following are some of the best practices to follow when encountered with Web App Firewall usage memory related issues:
nsconmsg command usage:
-
Look for global memory statistics to ascertain that there is enough memory in the system and there are no memory allocation failures by executing the following command:
* *- nsconmsg -d memstats
-
Observe current allocated and maximum memory limits for appsecure, IP reputation, cache and compression by executing the following command:
nsconmsg -d memstats | egrep -i APPSECURE|IPREP|CACHE|CMP
-
Check appfw, DHT, IP reputation activity counters by executing the following command:
nsconmsg -g as -g appfwreq_ -g iprep -d current
-
Check all Web App Firewall error counters by executing the following command:
nsconmsg -g as_ -g appfwreq_ -g iprep_ -d stats | grep err
-
Check all system error counters by executing the following command:
nsconmsg -g err -d current
-
Inspect for CPU, APPFWREQ, AS and DHT counters by executing the following command:
nsconmsg -g cc_cpu_use -g appfwreq -g as -g dht -d current
-
Check the configured Cache memory by executing the following command:
-
show cacheparameter
-
Check the configured memory by executing the following command:
nsconmsg -d memstats | egrep -i CACHE
-
Identify distribution of memory in Web App Firewall components and objects:
Display AS_OBJ_ memory:
nsconmsg -K newnslog -d stats | grep AS_OBJ | egrep -v AppFW_cpu0|total | sort -k3
Display AS_COMPONENT_ memory:
nsconmsg -K newnslog -d stats | grep AS_COMPONENT | egrep -v AppFW_cpu0|total | sort –k3
Check for number of alive sessions by executing the following command:
Monitor/plot active session counts:
nsconmsg -g as_alive_sessions -d current
Monitor/plot total allocated, free, updated sessions:
If required, reduce session timeout to ensure that session limits are not used by executing the following command:
set appfwsettings -sessionTimeout <300>
If required, set maximum lifetime of session by executing the following command:
set appfwsettings -sessionLifetime <7200>