Adobe 38043740 Lockdown Guide - Page 63

Server Settings > Request Tuning, Maximum number, of simultaneous, Template requests

Page 63 highlights

5.2 Server Settings > Request Tuning The Request Tuning settings can help mitigate the ability to perform a successful Denial of Service (DOS) attack on your server. Setting Maximum number of simultaneous Template requests Default 25 Maximum number 5 of simultaneous Flash Remoting requests Maximum number 5 of simultaneous Web Service requests Recommendation Description Tuned based on hardware capabilities, and application characteristics. When this setting is too high or too low the ability to perform a denial of service attack increases. When too low requests will be queued when the server is placed under load. When too high requests may not be queued under load causing the CPU time of all requests to increase significantly (known as context switching). Find a good medium by performing load tests against your production environment, use the value that has the ability to serve the most requests per second. 1 if not using Flash Remoting, otherwise tuned. If your applications do not use flash remoting set this value to 1. If you do use flash remoting use a load testing approach to find the optimal value for this setting. 1 if not using SOAP web services, otherwise tuned If your applications do not use SOAP web services set this value to 1. Otherwise tune this setting using load tests. 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

63
5.2 Server Settings > Request Tuning
The Request Tuning settings can help mitigate the ability to perform a successful Denial of Service (DOS)
attack on your server.
Setting
Default
Recommendation
Description
Maximum number
of simultaneous
Template requests
25
Tuned based on
hardware
capabilities, and
application
characteristics.
When this setting is too high or too
low the ability to perform a denial of
service attack increases. When too
low requests will be queued when
the server is placed under load.
When too high requests may not be
queued under load causing the CPU
time of all requests to increase
significantly (known as context
switching). Find a good medium by
performing load tests against your
production environment, use the
value that has the ability to serve the
most requests per second.
Maximum number
of simultaneous
Flash Remoting
requests
5
1 if not using Flash
Remoting,
otherwise tuned.
If your applications do not use flash
remoting set this value to 1. If you do
use flash remoting use a load testing
approach to find the optimal value
for this setting.
Maximum number
of simultaneous
Web Service
requests
5
1 if not using
SOAP web
services, otherwise
tuned
If your applications do not use SOAP
web services set this value to 1.
Otherwise tune this setting using
load tests.