Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid use all memory ram

    Scheduled Pinned Locked Moved Cache/Proxy
    43 Posts 16 Posters 15.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      emax4
      last edited by

      Hello…

      Ummmm .... yes, the problem is that if I disable the HTTPS / SSL Interception, the squidguard will not filter me the sites with ssl (https) certificate.

      On the other hand, it is interesting to enable the cron that you indicate me.

      I'll try those cron

      1 Reply Last reply Reply Quote 0
      • M
        miquim
        last edited by

        I have this problem too!
        any one has a update or downgread do works version?

        Tks!

        1 Reply Last reply Reply Quote 0
        • E
          emax4
          last edited by

          No one has solved the problem?

          1 Reply Last reply Reply Quote 0
          • gersonofstoneG
            gersonofstone
            last edited by

            I still have the problem

            Papu!! :V

            1 Reply Last reply Reply Quote 0
            • M
              miquim
              last edited by

              Me too,

              i just configure the cron for evey 30 min stop and start the squid service.

              You can install the Cron package and there you can add 2 news jobs

              */30 * * * * root /usr/local/sbin/squid -k shutdown
              */30 * * * * root sleep 10 && /usr/local/sbin/squid

              its work for me but is not the best solution.

              1 Reply Last reply Reply Quote 0
              • R
                remzej
                last edited by

                The swapstate_check.php won't execute because there is no cache partition mounted found in the filesystem. I checked the source code line by line and by creating a test.php from there I can tell that it will never execute because of the conditions doesn't meet. We can modify the swapstate_check.php to monitor the swap.state file size and clean the cache if this file exceeds the specified amount we set in the script.

                1 Reply Last reply Reply Quote 0
                • E
                  emax4
                  last edited by

                  Yes, for now I think the best solution is to use a cron to stop and knit the squid, as says miquim. I think we have to wait for an update to see if they solve the problem. If someone finds the solution, please advise

                  1 Reply Last reply Reply Quote 0
                  • R
                    remzej
                    last edited by

                    It's hard to monitor the swap.state filesize and the SWAP usage percentage because it grows dynamically. In my case I modified the swapstate_check.php code to execute if the cache folder size reach 250MB or the swap.state filesize reach 640KB.

                    1 Reply Last reply Reply Quote 0
                    • T
                      TomS
                      last edited by

                      I'm also seeing this memory exhaustion problem on my box. I do not use any disk cache and only want to be prepared to be able to block web sites just in case I'm told to do so by government authorities or law enforcement. Currently, I'm not blocking any websites. One more thing I'm currently doing with Squid is creating log files (i.e. which web sites have been opened by the users)
                      The system is an anonymous WiFi hotspot with approx. 300 users per day.
                      For some reason, the memory consumption is slowly increasing. At first only the memory itself, but later also the swap space until all the free memory is occupied and the pfSense is crashing.

                      I saw bbassotti's post and the configure differences in the squid versions… I'm using squid V 3.5.24 which has exactly the same configure options as V3.5.23 and it shows the same behavior... Could this be the root cause?
                      What else could be the reason for this strange behavior?
                      Is there anyone working on this issue? If there's a way I can contribute or help finding and fixing this issue, please just let me know.

                      Best,
                      TomS

                      1 Reply Last reply Reply Quote 0
                      • R
                        remzej
                        last edited by

                        @TomS:

                        I'm also seeing this memory exhaustion problem on my box. I do not use any disk cache and only want to be prepared to be able to block web sites just in case I'm told to do so by government authorities or law enforcement. Currently, I'm not blocking any websites. One more thing I'm currently doing with Squid is creating log files (i.e. which web sites have been opened by the users)
                        The system is an anonymous WiFi hotspot with approx. 300 users per day.
                        For some reason, the memory consumption is slowly increasing. At first only the memory itself, but later also the swap space until all the free memory is occupied and the pfSense is crashing.

                        I saw bbassotti's post and the configure differences in the squid versions… I'm using squid V 3.5.24 which has exactly the same configure options as V3.5.23 and it shows the same behavior... Could this be the root cause?
                        What else could be the reason for this strange behavior?
                        Is there anyone working on this issue? If there's a way I can contribute or help finding and fixing this issue, please just let me know.

                        Best,
                        TomS

                        This was posted as a bug for pfSense v2.3.x I read someone posted that this issue doesn't exist in pfSense v2.4 beta. We hope they will release an update soon to fix this problem.

                        1 Reply Last reply Reply Quote 0
                        • E
                          emax4
                          last edited by

                          @remzej:

                          @TomS:

                          I'm also seeing this memory exhaustion problem on my box. I do not use any disk cache and only want to be prepared to be able to block web sites just in case I'm told to do so by government authorities or law enforcement. Currently, I'm not blocking any websites. One more thing I'm currently doing with Squid is creating log files (i.e. which web sites have been opened by the users)
                          The system is an anonymous WiFi hotspot with approx. 300 users per day.
                          For some reason, the memory consumption is slowly increasing. At first only the memory itself, but later also the swap space until all the free memory is occupied and the pfSense is crashing.

                          I saw bbassotti's post and the configure differences in the squid versions… I'm using squid V 3.5.24 which has exactly the same configure options as V3.5.23 and it shows the same behavior... Could this be the root cause?
                          What else could be the reason for this strange behavior?
                          Is there anyone working on this issue? If there's a way I can contribute or help finding and fixing this issue, please just let me know.

                          Best,
                          TomS

                          This was posted as a bug for pfSense v2.3.x I read someone posted that this issue doesn't exist in pfSense v2.4 beta. We hope they will release an update soon to fix this problem.

                          Hopefully they will soon solve the problem, if anyone knows anything please let me know

                          1 Reply Last reply Reply Quote 0
                          • R
                            remzej
                            last edited by

                            I want to share my simple PHP code to monitor the memory and SWAP usage every 5 minutes using cron.

                            This PHP code will automatically stop and restart squid services when memory and SWAP usage goes beyond 90% and 75% respectively without deleting the existing hard disk cache and swap.state file. The swapstate_check.php script will handle it if swap.state file goes beyond 1GB size.

                            Attached here is the monitor_memory_usage.txt file you can download and save to your preferred location on your pfSense box. Don't forget to change the file extention from .txt to .php.

                            In my case I saved it in /usr/local/pkg/ directory. Don't forget to set the file permission to rwxr-xr-r.

                            Next thing to do, is to add a cron job that will look like this: (Be sure to install cron package to be able to do this)

                            */5 * * * * root /usr/local/pkg/monitor_memory_usage.php

                            then save it. That's it! I hope this simple hard work and research will help some of you that has high memory usage problem.

                            Thanks!
                            remzej

                            monitor_memory_usage.txt

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              Thanks for the contribution. :)

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • gersonofstoneG
                                gersonofstone
                                last edited by

                                @marcelloc:

                                Thanks for the contribution. :)

                                this change was in last update for squid?

                                Papu!! :V

                                1 Reply Last reply Reply Quote 0
                                • marcellocM
                                  marcelloc
                                  last edited by

                                  @😄:

                                  this change was in last update for squid?

                                  Not sure, it was updated recently. Did you updated the package?

                                  Treinamentos de Elite: http://sys-squad.com

                                  Help a community developer! ;D

                                  1 Reply Last reply Reply Quote 0
                                  • gersonofstoneG
                                    gersonofstone
                                    last edited by

                                    Update squid to 1.16.2

                                    And make changes

                                    • SystemAdvancedFirewall & NAT
                                      Firewall Optimization Options Agrresive

                                    • IP Do-Not-Fragment compatibility
                                      Clear invalid DF bits instead of dropping the packets

                                    *Disable Firewall Scrub
                                    Disables the PF scrubbing option which can sometimes interfere with NFS traffic.

                                    • SystemAdvancedNetworking

                                    Hardware Checksum Offloading *Disable
                                    Hardware TCP Segmentation Offloading *Disable
                                    Hardware Large Receive Offloading *Disable

                                    this for NIC realteck

                                    :)

                                    Papu!! :V

                                    1 Reply Last reply Reply Quote 0
                                    • R
                                      remzej
                                      last edited by

                                      Latest squid package v0.4.37 already fixed this bug.

                                      1 Reply Last reply Reply Quote 0
                                      • G
                                        Gravitator
                                        last edited by

                                        Hello!

                                        Version PFSense:

                                        2.3.4-RELEASE (i386)
                                        built on Wed May 03 15:22:11 CDT 2017
                                        FreeBSD 10.3-RELEASE-p19

                                        Latest squid package v0.4.37 with SquidGuard 1.16.2 in transparent mode with SSL interception (strip all).

                                        Gradually increasing memory consumption, the overflow resets.

                                        @😄:

                                        Update squid to 1.16.2

                                        And make changes

                                        • SystemAdvancedFirewall & NAT
                                          Firewall Optimization Options Agrresive

                                        • IP Do-Not-Fragment compatibility
                                          Clear invalid DF bits instead of dropping the packets

                                        *Disable Firewall Scrub
                                        Disables the PF scrubbing option which can sometimes interfere with NFS traffic.

                                        • SystemAdvancedNetworking

                                        Hardware Checksum Offloading *Disable
                                        Hardware TCP Segmentation Offloading *Disable
                                        Hardware Large Receive Offloading *Disable

                                        this for NIC realteck

                                        :)

                                        These settings did not help.

                                        Will the transition to x64?

                                        1 Reply Last reply Reply Quote 0
                                        • E
                                          emax4
                                          last edited by

                                          Hello gravitator

                                          With the update of Squid is enough for the solution of the problem, greetings!

                                          1 Reply Last reply Reply Quote 0
                                          • G
                                            Gravitator
                                            last edited by

                                            @emax4:

                                            Hello gravitator

                                            With the update of Squid is enough for the solution of the problem, greetings!

                                            Hello…

                                            Unfortunately, you have the latest version of package squid - 0.4.37. The problem is not resolved.
                                            Pfsense is also updated to the version from 20.07.2017.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.