SPICE Proxy with haproxy

2015-06-10 Thread Kevin C
Hi list,

Is it possible to use HAproxy instead of Squid for a SPICE Proxy (I already 
use Haproxy on this server, I'd rather avoir to install Squid) ? 

I try this 

 oVirt  +SPICE
frontend fe_spice_proxy
bind 172.18.1.99:8080
#bind 172.18.1.99:5900-6123
option tcpka
default_backend bk_OVIR
##
backend bk_OVIR
option tcpka
balance roundrobin
server OVIR1 172.20.69.21:5900-6123 weight 10
server OVIR2 172.20.69.22:5900-6123 weight 10


But it seems I can't set a port range in the server directive. Somebody have 
an idea how  can I setup ?

Thanks a lot
-- 
Kevin



See You at the Guzhen Lighting Fair to Share

2015-06-10 Thread Guzhen Lighting Fair
See You at the Guzhen Lighting Fair to Share

Hello haproxy@formilux.org,

看上去似乎您的e-mail软件不支持HTML。
请访问下面的网页使您能够在网页浏览其中阅读这条信息:
http://edm.ubmsinoexpo.com/x/?S7a1MPufa2tuYGLyv8jW0tDMzOR.jq2lpYEBAAA25

Re: SPICE Proxy with haproxy

2015-06-10 Thread Malcolm Turnbull
Kevin,

Simply remove the port and HAProxy will use the original one:

server OVIR1 172.20.69.21 weight 10



On 10 June 2015 at 09:29, Kevin C ki...@kiven.fr wrote:
 Hi list,

 Is it possible to use HAproxy instead of Squid for a SPICE Proxy (I already
 use Haproxy on this server, I'd rather avoir to install Squid) ?

 I try this

  oVirt  +SPICE
 frontend fe_spice_proxy
 bind 172.18.1.99:8080
 #bind 172.18.1.99:5900-6123
 option tcpka
 default_backend bk_OVIR
 ##
 backend bk_OVIR
 option tcpka
 balance roundrobin
 server OVIR1 172.20.69.21:5900-6123 weight 10
 server OVIR2 172.20.69.22:5900-6123 weight 10


 But it seems I can't set a port range in the server directive. Somebody have
 an idea how  can I setup ?

 Thanks a lot
 --
 Kevin




-- 
Regards,

Malcolm Turnbull.

Loadbalancer.org Ltd.
Phone: +44 (0)330 1604540
http://www.loadbalancer.org/



gabinetes inquiry

2015-06-10 Thread alvin
Dear Purchasing manager,

How are you ? i am glad to contact with you.

We are a leading company with many years' experience in pc case and power 
supply business. Our case products included case ATX,MICRO ATX,SLIM and GAMING 
and power supply from 200w to 1200W.You may also visit our website 
introduction, which includes our latest product line.

Should any of these items be of interest to you, please let us know. We will be 
happy to give you a quotation upon receipt of your detailed requirements.We 
look forward to receiving your enquires soon. 
Sincerely,

Mr Alvin/Manager

SHENZHEN SHUNXINJIE INDUSTRIAL CO.,LTD
Email:alvin_...@yahoo.com
Direct tel: 86 755 26461878
Tel: 86 755 27317289-823
Fax: 86 755 26078695
Website: www.shunxinjie.com

CE RoHS approved 10w/20w/30w/50w rgb led floodlight

2015-06-10 Thread kathy

  
  

  Hello,
  

  
High power 150W led floodlight 9000lm IP65 waterproof .

  30W led floodlight Mean Well driver 25$usd 
  50W led floodlight Mean Well driver 32$usd 
  700W led floodlight Mean Well driver 59$usd 
  100W led floodlight Mean Well driver 79$usd 
  200W led floodlight Mean Well driver 128$usd 
  
  We supply led lamp with high quality and competitive price. Hope to cooperate with you.
  
  Best Regards
  --
  Kathy Wu
  Skype: kathystar11
  JIN WANG Optoelectronics Co., Limited
  T: 0086 0755 33165048 


  

  

  


Re: Configuration help with SPDY Virtual Hosts

2015-06-10 Thread Viranch Mehta
Bump. Turns out a bunch of scripts/programs hit my sites that don't do
SNI. Any ideas?

I don't seem to be able to parse HTTP headers with TCP frontend.

On Mon, Jun 8, 2015 at 6:10 PM, Lukas Tribus luky...@hotmail.com wrote:
 Also more importantly, can I use proxy protocol with TCP backends? I
 need TCP backends to support SPDY.

 Yes, thats exactly the point of the proxy protocol.


 Lukas





[SPAM] competitive LED Panel light

2015-06-10 Thread Mr. Wengang Xu
Dear Sir

Good day!

We would like to recommend one our of High CRI LED Panel 36W as follows:

Art No: XD-PL595-36W
Power: 36W
Voltage: 85~265V AC
CRI: 80
P.F.: 0.9
Lumens: 3000~3200lm
CCT: 2700~6500K
Size: 595 x 595mm
CE RoHS approval


We hope we have chances to establish long term business relations with you and 
looking forward to your kindly reply soon.

ThanksBest regards

Wengang Xu

Zhongshan Xiding Electrical Equipment Co.,Ltd. 
HK XIDING GROUP CO.,LIMITED
Address:Xiding Building,No 22,Xinmao Industrial Avenue, Henglan Town, Zhongshan 
City, Guangdong province, China.
Tel: 0086-186-7480-7320 
What'sApp: 0086-186-7480-7320
Skype: whitexwg
attachment: 1370592616.jpg


Healthcare Leads

2015-06-10 Thread Shelly Nelson
Hello,

 

Would be interested in acquiring Healthcare Leads with verified business
emails and complete contact information.

 

Whether you are marketing to dentists, nurses, or any of the roughly 800
specialty and facility types in our database, We can help you hit them,
providing comprehensive information on all HIPAA-covered U.S. healthcare
providers - in specific geographic areas and matching particular demographic
profiles. Providers and facilities include, among others:

 

 


Acupuncturists

Genetic Counselors

Pathologists


Addiction Medicine

Geriatrics

Pediatric Anesthesiology


Adolescent Medicine

Gynecologists

Pediatricians


Aerospace Medicine

Hematologists

Pharmacies


Allergists  Immunologists

Home Health Agencies

Pharmacies


Alternative Medicine Practitioners

Hospices

Pharmacists


Alzheimer Centers

Hospitalists

Phlebologists


Ambulance Services

Hospitals

Physical Therapists


Ambulatory Care Facilities

Hyperbaric Medicine

Physicians (specifying 200+ specialties)


Anesthesiologists

Internal Medicine

Plastic Surgeons


Art, Dance  Music Therapists

Laboratories

Podiatrists


Assisted Living Facilities

Massage Therapists

Prosthetists


Audiologists

Medical Students

Psychiatric Hospitals


Blood Banks

MRI

Psychiatrists


Cardiologists

Neurological Surgeons

Psychologists


Cardiopulmonary Specialists

Neurologists

Psychosomatic Medicine


Children's Hospitals

Neuromusculoskeletal

Public Health Agencies


Chiropractors

Neuropathology

Radiological Technicians


Counselors

Nuclear Medicine

Radiologists


Critical Care Surgeons

Nurses

Respite Care Facilities


Dental Hygienists

Nursing Facilities

Sleep Medicine


Dentists

Obstetricians

Specialty Hospitals


Dermatologists

Occupational Therapists

Speech Therapists


Dieticians  Nutritionists

Oncologists

Sports Medicine


Durable Medical Equipment

Ophthalmologists

Surgeons


Emergency Medicine

Optometrists

Therapists


Endocrinologists

Oral  Maxillofacial Surgeons

Transplant Surgeons


Family Practice Physicians

Orthopedics

Urgent Care Centers


Forensic Psychiatrists

Otolaryngology

Urologists


Foster Care Agencies

Pain Specialists

Women's Hospitals

 

Please let me know your thoughts so that I can send you some samples and
more details regarding this and a convenience Time to call, and other
Services.

 

Await your response.

 

Best Regards,

 

Shelly Nelson| Business Developer

shelly.nel...@iqualifyleads.com

 

If you do not wish to receive any further emails from us, please reply
Unsubscribe in the subject line

 



iPhone Users Contacts

2015-06-10 Thread Mark Jenkins
 

 

Hi,

 

Hope this email finds you well!

 

 

Would you be interested in acquiring email list of  iPhone Users Contact
List across USA?

 

We have data for iPhone Users, Android Users, iOS Users, Windows Users, iMac
Users, PC Users, Tablet Users and more..

 

Each record in the list contains Contact Name (First, Middle and Last Name),
Direct-Mailing Address (Address1, Address2, City, State, Country, Zip, IP
address), List type and Opt-in email address.

 

All the contacts are opt-in verified, 100% permission based and can be used
for unlimited multi-channel marketing.

 

Please let me know your thoughts towards procuring the iPhone Users Contact
List.

 

 

Kind Regards,

Mark Jenkins 

Research Analyst

 

 

 

 

If this message is not relevant to you please forward to decision maker

 

 

 

We respect your privacy, if you do not wish to receive any further emails
from our end, please reply with a subject Leave Out.

 



Re: High performance HAProxy

2015-06-10 Thread Willy Tarreau
Hi Eduard,

On Wed, Jun 10, 2015 at 04:56:31AM +, Eduard Rushanyan wrote:
 With few folks here we had some learning and already are experiencing quite
 good results with HAProxy. Wanted to first of all share that during the tests
 we achieved up to 45,000 requests per second on SSL on a single 1G box (with
 same setup/hw below). isn't that amazing? :) 

It's independant on the network connectivity. It also depends whether
you're doing it in keep-alive, with close and TLS resume, or with a
new renegociation on each request. Given the numbers, I'm assuming
that you're in TLS resume mode, because the numbers would seem high
for renegociation (typically 500-1000 per core) and low for requests
(typically 10 per core).

 Also wanted to ask for your opinion or advise on how we can possibly improve
 the setup further. It really feels like there is something more out there and
 we could tune up the setup further. 

I'm seeing room for improvement, as it's clear that you're not getting
the most out of your machine. We usually observe around 1 conn/s
per core in TLS resume, so you're still far from this.

 Our use case is: 
 - high request per second traffic (very high PPS/packet per second) 
 - HTTPS 
 - hundreds of thousands of requests per second 
 - gigabytes of traffic /per second 
 - currently handled by hardware LoadBalancers -- aim to replace hardware
   LoadBalancers with HAProxy 
 
 What do we have currently in HAProxy: 
 Rate: 26,000 HTTPS requests per second, per single HAProxy server 
 CPU idle: 50% 
 System avg load: 8 
 Software IRQs %: ~10% 
 
 What would be great to have: 
 - reduced system load 
 - more idle CPU 
 - ability to push more bandwidth or more requests per second 
 - no Software IRQs (or less), possibly less context switches/interrupts 

You'll have to pick 1 from the last 3 :-)

 Do you think it's possible to further improve current setup
 software/configuration wise? 

First I'm seeing a number of things you can change in your config.

1) all the stats instances can be simplified to a single one with
   all the individual ports, making it much simpler to declare and
   the config easier to read :

   listen stats
   bind :4001 process 1
   bind :4002 process 2
   ...
   bind :4024 process 24
   mode http
   stats enable
   stats hide-version
   stats realm Haproxy\ Statistics
   stats uri /
   stats auth someuser:somepass

2) you didn't specify any process binding in ssl_termination, so the
   kernel wakes all processes with incoming connections, and a few of
   them take some and the other ones go back to sleep. With a kernel
   3.9 or later, you can multiply the bind lines and bind each of them
   to a different process. The load will be much better distributed :

   listen ssl_termination
   bind 0.0.0.0:443 process 1 ssl crt /webapps/ssl/haproxy.new.crt ciphers 
AES-128-CBC:HIGH:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!AESGCM no-ssl3
   bind 0.0.0.0:443 process 2 ssl crt /webapps/ssl/haproxy.new.crt ciphers 
AES-128-CBC:HIGH:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!AESGCM no-ssl3
   ...

3) you're chaining the SSL instances to the clear-text instance,
   thus doubling the internal connection rate. In general this ensures
   that you have a single process which handles all the traffic, but in
   your case that's not true since all 24 processes can randomly receive
   the connection :

   listen ssl_termination
   bind 0.0.0.0:443 ssl crt /webapps/ssl/haproxy.new.crt ciphers 
AES-128-CBC:HIGH:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!AESGCM no-ssl3
   server cleartext_http abns@haproxy-clear-listener send-proxy-v2

   frontend cleartext_http
  bind 0.0.0.0:80
  bind abns@haproxy-clear-listener accept-proxy
  default_backend lb_backend

   I'd suggest that you either avoid this bouncing or limit the number
   of processes listening to clear text. If you're fine with running
   the backend and cleartext frontend on all processes, then you can
   simply pu the default_backend rule in ssl_termination instead
   of server.

4) as you can see in /proc/interrupts, the ethernet interrupts are
   spread over all threads of the first CPU socket, so the haproxy
   processes running on the same cores are competing with the softirq
   on the same threads, forcing the load to be unequal.

The last point is the trickiest to adjust and you'll have to experiment
a lot. In general, what is important to know :
  - avoid inter-CPU communications as much as possible, as they come
with latency and cache flushes ;

  - SSL processing is still faster on multiple CPU sockets than what
you save by avoiding such communications above.

Given that you're limited to 1 Gbps, the softirq load will remain very
low so in my opinion you should limit your IRQs to just a few cores.
Note that using threads for IRQs is interesting because it increases
cache locality and still provides a nice boost (I've observed about
20% perf increase by using 2 

Devenez propriétaire aux meilleures conditions

2015-06-10 Thread Bouygues Immobilier via VisiteOnline
Title: Bouygues Immobilier
  Si ce message ne s'affiche pas correctement, visualisez la version en ligne.













  












 
  Dites OUI  un logement facile  acheter !
 
 



































ACHETER DANS LE NEUF ?
















  


















  
  
  
  
  

  



  



  




  



  
  
  

[SPAM] Re:LED panel light for sale

2015-06-10 Thread Carina
=20 Hey guy, Pleased to hear that you are on=nbsp;the market of LED lighting 
products.  Carina=from Asia-Boslin here, exporting LEDlightproduct=s with good 
quality and competitive pric=e. E-c=atalog will be provided if needed. Email me 
or j=ust call me directly, let's talk details=.Thank 
you!Rgds,CarinaChenAsia-BOSLI=NoptoelectronicsSciamp;TechGroupCO.,LIMITEDFactoryADD:TaiHeRongIndustrialBldgA=.LiaoKeng.Shiyan,Shenzhen(518108)
 
OfficeA=DD:Room722,Building523,BaGuaLingIndustrialpark,BaGuaThirdRd,F=utiandistrict,shenzhenChina
 Mobile:+86-1536168098=0Fax:+86-755-23007107 
SkypeID:Simaoled30E-mail:car...@simaoled.com 
=Website:www.simaoled.comnbsp=;nbsp=;Belowplsfindtheinformation=of600*600mmLEDpanellight36Wforyourreference:
  = MS-PL18323 Power = 36W=nbsp;Packingdetails:4pcs/Car=ton  
nbs=p;   CartonSize:L68times;W64times;H18=cm GW:14.5kg/Carton 
UnitPriceUS$18.00 Size L597*W597*T13mm InputVoltage AC85-265V/AC50/60Hz 
LEDQTYnbs=p;80pcs =LEDTypenb=sp;5630SMDchip CCT 2700-6500K=nbsp;Lumen 
=3200LMnbsp=;Powerfactor 0.93 CRI(Ra)nb=sp;Ra#65=310;75 
Materialnb=sp;PureAluminum Lifespannb=sp;gt;50,000hours 
Tounsubscribe,pleaseclickhere

HAProxy Redirects Of Domain Domain w/Subdomain

2015-06-10 Thread BGaudreault Brian
Hello,

I'm trying to redirect a domain and 1 other subdomain of that domain, but it's 
not working (2 other redirects work to https, but they're both different 
domains from each other and from this domain in question) and I haven't been 
able to find an example that matches my configuration.

Here's a snippet of the code in the order the entries appear, but let me know 
if you think you need to see more of the code (a lot of front ends and backends 
exist).

acl is_test1.domain.com hdr_dom(host) -i test1.domain.com
acl is_domain.com hdr_dom(host) -i domain.com

redirect location https://test1.domainTwo.com/ if is_domain.com
redirect location https://test1.domainTwo.com/path/ if is_test1.domain.com

Also, how should www.domain.comhttp://www.domain.com be handled with this 
configuration?  Do I need another acl for it?

Thanks,
Brian


RE: Configuration help with SPDY Virtual Hosts

2015-06-10 Thread Lukas Tribus
 Bump. Turns out a bunch of scripts/programs hit my sites that don't do
 SNI. Any ideas?

Virtual HTTPS hosting needs SNI. If your clients/script doesn't support SNI,
you cannot host more than one certificate with one IP.

Doesn't have anything todo with SPDY or Haproxy, its just how things are.

If you don't have different webseits (domains), use a default-backend.




Lukas 


Re: Configuration help with SPDY Virtual Hosts

2015-06-10 Thread Viranch Mehta
On Wed, Jun 10, 2015 at 8:45 PM, Lukas Tribus luky...@hotmail.com wrote:
 Bump. Turns out a bunch of scripts/programs hit my sites that don't do
 SNI. Any ideas?

 Virtual HTTPS hosting needs SNI. If your clients/script doesn't support SNI,
 you cannot host more than one certificate with one IP.

I've got a wildcard cert *.foo.com, so I guess that takes care of it(?).