It's all about the answers!

Ask a question

How much impact of network connection to LDAP on CLM performance?


Frank Ning (50025119133) | asked Nov 18 '12, 9:37 p.m.
retagged Nov 19 '12, 4:02 p.m. by Ginny Ghezzo (33311117)
Hello,

The network connection among CLM VMs (WAS cluster nodes, DB2, proxy servers) is about 1GiB/s. The CLM is configured with MS AD to manager users. However, the MS AD VM is on another network and the network connection from CLM to the MS AD is about 300Mbps.

I am wondering how much impact of the connection speed to MS AD on CLM performance? Should I need to created a MS AD server within the same network to take advantage of  the 1GiB/s connection speed?

Thanks and regards

2 answers



permanent link
Ralph Schoon (63.5k33646) | answered Nov 19 '12, 5:39 a.m.
FORUM ADMINISTRATOR / FORUM MODERATOR / JAZZ DEVELOPER
I would expect minimal impact, because I assume LDAP gets only involved when logging in. I think the clients keep the connection open.

Comments
Frank Ning commented Nov 19 '12, 8:08 p.m.

Hi Ralph,

Thanks for the information. How about the impact on the 1st logon page?


Ralph Schoon commented Nov 20 '12, 1:10 a.m.
FORUM ADMINISTRATOR / FORUM MODERATOR / JAZZ DEVELOPER

I would try and if people complain, I think it would be relatively easy to change the LDAP settings. You could also set up a test system first.


Nhi P Ta commented Nov 20 '12, 1:46 a.m.

Hi Frank,

On our environment which access a LDAP server via an firewall the first logon varies between 60-90 sec, subsequent logon took less then 30sec.


Frank Ning commented Nov 20 '12, 9:30 a.m.

Hi Nhi,

Thanks for the information. 30sec is still long to me:-)

Is the firewall setup within your CLM proxy/servers? Or on the network(domain) layer outside your systems?

Thanks


Frank Ning commented Nov 20 '12, 11:05 a.m.

Hi Ralph,

Here are the scenarios:

1. Subnet A: LDAP, CLM1
2. Subnet B: CLM2 (more RAM and CPU cores than CLM1) using LDAP in Subnet A

I found accessingCLM2 is quite slower than accessing CLM1. I am checking if the LDAP is the cause or the firewall between these two subnets is causing this. Some tips are appreciated.




Nhi P Ta commented Nov 25 '12, 10:47 p.m.

Hi Frank, 


The firewall was at the networking layer. In IBM terms a yellowzone server that query our LDAP server in the bluezone. 

showing 5 of 6 show 1 more comments

permanent link
Stephane Leroy (1.4k149) | answered Nov 26 '12, 5:32 a.m.
JAZZ DEVELOPER
Hi Frank,

if using  Federated Registry, you might want to read this recent article :

Optimizing performance with WebSphere LDAP Configurations

Regards,

Stéphane

Your answer


Register or to post your answer.


Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.