Dne středa 1. dubna 2020 15:47:09 CEST, Andrea Venturoli via clamav-users napsal(a): > Hello. > > I'm trying the combination Squid + C-ICAP + SquidClamAV + ClamAV, and > I'm seeing terrible performance. > It seems there's no SquidClamAV specific mailing list and asking on > generic Squid list did not help much. > Perhaps someone here is using the same thing or knows how to better > tweak the engine.
Hello, few years ago I used squid + c-icap + clamav (without squidclamav), and it worked fine. I'm not sure why I stopped using it, maybe it broke on server upgrade or something. (And I had good antivirus on clients anyway). > The whole thing is working, but page loading times varies a lot: > sometimes they'll load as fast as without virus scanning, but often (the > same pages) will take several seconds to display (with ClamAV eating a > lot of CPU). > I tried to see what is being scanned, but since SquidClamaAV uses inline > connections, clamdtop seems to be helpless. Are you running clamav as daemon? Is c-icap using the daemon socket (as if runing clamdscan)? If not it might be spawning clamscan for every downloaded page, and the startup of clamav takes very long time (parsing all the rules). Also check if you have enough memory both clamav and squid can eat a lot, so check if you are not swapping. Best Regards Vladislav Kurz _______________________________________________ clamav-users mailing list clamav-users@lists.clamav.net https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml