Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Login is very slow - possible auditing problem?

Posted on 2008-06-19
9
Medium Priority
?
931 Views
Last Modified: 2013-12-06
Logging into our AIX systems is sporadically very slow (ie - minute(s) instead of 2 seconds.  After debugging our login scripts, I've come to think that this is a network issue or related to auditing in some way.  I found this on IBMs site:
    IZ22120: POOR NFS COPY PERFORMANCE ON 6.1 WITH AUDITING ENABLED
but we're also seeing this on our AIX 5.3 systems, as well as our 6.1 systems.  
I'm looking for ideas on how to debug this issue.  Note that I am not a sys admin and therefore don't have access to root.  Sys admins are available but not dedicated to solving this problem.
0
Comment
Question by:sjpetrov
9 Comments
 
LVL 32

Expert Comment

by:Kamran Arshad
ID: 21821987
Hi,

Possibly you can start Wireshark and run it before logging. This will give you traces of any possible network errors.

www.wireshark.org

If you are new to WireShark:

wiki.wireshark.org
0
 
LVL 4

Accepted Solution

by:
robertfwoods earned 600 total points
ID: 21822051
It is very important that your network DNS is functioning properly.
The AIX machines must be configured properly to "know who they are".
At login time the process checks the host name against the DNS structure.
The timeout period you are seeing may be the DNS timeout.

Troubleshoot using
nslookup - -
Then enter the hostname of the server
Also enter the hostname.domainname.com
Time the return.

This structure is controlled by three files
/etc/hosts
/etc/resolv.conf
/etc/netsvc.conf

Read about them at:
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp 
In the Left panel, navigate to:

AIX documentation>Files reference>System Files>netsvc.conf
AIX documentation>Files reference>File Formats>hosts File...
AIX documentation>Files reference>File Formats>resolv.conf

0
 

Author Comment

by:sjpetrov
ID: 21822058
Unfortunately, it's on a classified network and analyzers such as this are forbidden.  Great idea, though.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 16

Expert Comment

by:Hanno P.S.
ID: 21825197
In most of these cases the host has problems resolving it's own name when
you log in.
Try resolving with
  telnet hostname
with hostname being the host's own name.

If this does take long (sometimes!), try adding the "official" host name (either
the short name ot the FQDN (hostname including full domain) into /etc/hosts
and try again.

If this solves your problem, you might haev a problem with name resolution.
Depending on your entry for "hosts = " in /etc/netsvc.conf you will have to
check
  a) DNS
      # nslookup hostname
  b) NIS (aka YP)
      # ypmatch hostname hosts
      or
      #ypcat hosts | grep hostname


0
 
LVL 62

Assisted Solution

by:gheist
gheist earned 400 total points
ID: 21842586
Most likely it is DNS problem - your host has no reverse PTR record.

on aix system do host (your_ip)

it waits same...
0
 
LVL 1

Expert Comment

by:duraisamy
ID: 21844265
Do u have any unwanted IP entry in /etc/resolv.conf file? If yes,  it will delay the login process.
Regarding the NFS, Incase you have any NFS volume with automatic mount, try to replace the hostname with IP address and try.
We had the same problem with login and fixed with above options.
0
 
LVL 16

Expert Comment

by:Hanno P.S.
ID: 21844774
we all will have to wait until the asker comes back after checking his DNS setup ...
0
 

Author Comment

by:sjpetrov
ID: 21845043
My Sys Admin has fixed the problem but isn't being forthcoming with what he did, though I know the reverse DNS was fixed, at a minimum.  Thanks for all of the great ideas!
0
 

Author Closing Comment

by:sjpetrov
ID: 31468744
Only problem was on my end, getting and giving info to my sys admin.  
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

FreeBSD on EC2 FreeBSD (https://www.freebsd.org) is a robust Unix-like operating system that has been around for many years. FreeBSD is available on Amazon EC2 through Amazon Machine Images (AMIs) provided by FreeBSD developer and security office…
Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Suggested Courses
Course of the Month10 days, 23 hours left to enroll

886 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question