Dedicated Apache for modsecurity, what is recommended MPM?
highclass99 <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CACk6sOt=7Eu8Yqg3ZBeKTqTG1eP0Yp6WnSUwd8JGxg-nAoQLtA@mail.gmail.com> |
Hello, I run a nginx <-> static files nginx <-> apache modsecurity proxy <-> nginx <-> dynamic files(fastcgi) configuration. So, apache is only 100% for WAF. In this case my theory was that since apache modsecurity is probably not io bound but cpu bound, I set the apache MPM as prefork. This apache instance handles thousands of requests/sec. I could not find any good information on whether this is optimal performance wise. Performance wise is this a better choice than worker or event MPM, when considering the apache is 100% only modsecurity requests? Also, I used the above model because nginx modsecurity was too buggy in the past, I am considering using modsecurity 3 with nginx. In that case would it be optimal to increase nginx worker instances since modsecurity would probably be cpu bound? _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/