@cryptotaxi247 / netdata-1 / commits / 8b53dfc67

Docs: Add notice about mod_evasive to Apache proxy guide (#7578)

* Add text about mod_evasive * Bit more text * More text

Joel Hans committed Dec 18, 2019 at 11:58 UTC 8b53dfc6778f8923f4e4fb4ef9b04b855b2b5796
1 file changed +29
docs/Running-behind-apache.md
+29
@@ -227,6 +227,35 @@ If you want to enable CSP within your Apache, you should consider some special r
227
228 Note: Changes are applied by reloading or restarting Apache.
229
230 +## Using Netdata with Apache's `mod_evasive` module
231 +
232 +The `mod_evasive` Apache module helps system administrators protect their web server from brute force and distributed
233 +denial of service attack (DDoS) attacks.
234 +
235 +Because Netdata sends a request to the web server for every chart update, it's normal to create 20-30 requests per
236 +second, per client. If you're using `mod_evasive` on your Apache web server, this volume of requests will trigger the
237 +module's protection, and your dashboard will become unresponsive. You may even begin to see 403 errors.
238 +
239 +To mitigate this issue, you will need to change the value of the `DOSPageCount` option in your `mod_evasive.conf` file,
240 +which can typically be found at `/etc/httpd/conf.d/mod_evasive.conf` or `/etc/apache2/mods-enabled/evasive.conf`.
241 +
242 +The `DOSPageCount` option sets the limit fo the number of requests from a single IP address for the same page per page
243 +interval, which is usually 1 second. THe default value is `2` requests per second. Clearly, Netdata's typical usage will
244 +exceed that threshold, and `mod_evasive` will add your IP address to a blocklist.
245 +
246 +Our users have found success by setting `DOSPageCount` to `30`. Try this, and raise the value if you continue to see 403
247 +errors while accessing the dashboard.
248 +
249 +```conf
250 +DOSPageCount 30
251 +```
252 +
253 +Restart Apache with `sudo service apache2 restart`, or the appropriate method to restart services on your system, to
254 +reload its configuration with your new values.
255 +
256 +See issues [#2011](https://github.com/netdata/netdata/issues/2011) and
257 +[#7658](https://github.com/netdata/netdata/issues/7568) for more information.
258 +
259 # Netdata configuration
260
261 You might edit `/etc/netdata/netdata.conf` to optimize your setup a bit. For applying these changes you need to restart Netdata.