12-09-2016 06:18 AM
Over time our S170 web UI is painfully slow to simply log in and do ANYTHING. I just wasted 10 minutes of time just getting logged in and going to policy trace to check why a site is blocked for a particular user.
Any idea why this thing has such poor performance? Is there a better solution out there that can replace an S170? Sophos, Websense, a different Cisco product, etc...?
Were on 9.1.1-074 but I see 9.1.2 build 010 is available for upgrade. Should I upgrade?
How easy would it be to convert this thing into a vmware appliance for web filtering, but still keep the S170 for the hardware layer 4 inspection?
12-17-2016 05:11 PM
Check the reporting in the appliance, is the reporting showing the data?
Also in the CLI of WSA go to diagnostic -> reporting -> dbstats, the result shows more than 1000 files for export files and always onbox, would recommend to disable the reporting first (CLI-> reporting->disable) then perform deleteexportdb and deletejurnal.
Deleting the above will not delete your reporting database, it is just deleting the tmp files in the database that seems to be stucked (this is a known issue if you upgraded from version 9.0.1 to version 9.1.1).
Also make sure your RAID is optimal as well if its showing degraded then one of the disk might be failing that can caused that (CLI -> version).
for version 9.1.2, see below for the release note:
http://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa9-0/wsa9-1/WSA_9-1-x_Release_Notes.pdf
01-03-2017 06:58 AM
This is what I get from dbstats:
Outstanding DB stats:
Export Files:
Folders: 2
Files: 96
Always Onbox:
Folders: 1
Files: 2
The reporting system is currently enabled.
Should I still run the deleteexportdb and deletejournal? Raid status shows optimal.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide