From owner-freebsd-questions@FreeBSD.ORG Wed Feb 10 18:36:44 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F4160106568B for ; Wed, 10 Feb 2010 18:36:43 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: from mail-qy0-f189.google.com (mail-qy0-f189.google.com [209.85.221.189]) by mx1.freebsd.org (Postfix) with ESMTP id A99D38FC12 for ; Wed, 10 Feb 2010 18:36:43 +0000 (UTC) Received: by qyk27 with SMTP id 27so298507qyk.3 for ; Wed, 10 Feb 2010 10:36:42 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:content-type :content-transfer-encoding; bh=F5ljpxaSzyec1vNMjf8WlHemCcJgqxZdy3amhHBONxI=; b=v+hzD5ljlG8X9vC4ORPnDbpj35aRPBUQyYpvg5vH04tjZP5eWrblxXm2dSaEYotErz txt+8gRv6vSG5fdanoHsQZrjE1G/9/Wh39yZRL6RIsHhnhK3Y6sNJY32rq9FW25GFcTB fTfPAK5pA7hp+w5FDW1mfisF2uGE1B52wZTFk= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; b=ZS9gU1eeKXXLySNBUuXNkKwrIpSeSTX4cHKsRtuyvZfjm5CndTfkBhBlqPucpFeYfM VZUdrSx+khX/THRE34hmrU4ZjI0ktB7fQVgULgatmI9IpCUrYiLMcFGe5NhLvjAb13Mc T9758mrFsyj2ibR2+j1egAlH6RHlo1qKHMykA= MIME-Version: 1.0 Received: by 10.224.16.200 with SMTP id p8mr370988qaa.176.1265827002792; Wed, 10 Feb 2010 10:36:42 -0800 (PST) In-Reply-To: <20100210180329.GA9318@dan.emsphone.com> References: <20100210050518.GA64193@dan.emsphone.com> <20100210180329.GA9318@dan.emsphone.com> Date: Wed, 10 Feb 2010 10:36:42 -0800 Message-ID: From: Kurt Buff To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Subject: Re: curl question - not exactly on-topic X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 10 Feb 2010 18:36:44 -0000 On Wed, Feb 10, 2010 at 10:03, Dan Nelson wrote: > In the last episode (Feb 10), Kurt Buff said: >> On Tue, Feb 9, 2010 at 21:05, Dan Nelson wrote= : >> > In the last episode (Feb 09), Kurt Buff said: >> >> Actually, it's not merely a curl question, it's a "curl and squid" >> >> question. >> >> >> >> I'm trying to determine the cause of a major slowdown in web browsing= on >> >> our network, so I've put curl on the squid box, and am using the foll= owing >> >> incantations to see if I can determine the cause of the slowdown: >> >> >> >> =C2=A0 curl -s -w "%{time_total}\n" "%{time_namelookup}\n" -o /dev/nu= ll http://www.example.com >> >> >> >> and >> >> >> >> =C2=A0 curl -s -w "%{time_total}\n" "%{time_namelookup}\n" -o /dev/nu= ll -x 192.168.1.72 http://www.example.com >> >> >> >> The problem arises with the second version, which uses the proxy. The >> >> first incantation just returns the times, which is exactly what I wan= t. >> >> >> >> However, when I use the -x parameter, to use the proxy, I get html >> >> returned as well as the times, which is a pain to separate out. >> > >> > Your problem is what's after -w. =C2=A0You want one argument: >> > "%{time_total}\n%{time_namelookup}\n", not two. =C2=A0=C2=A0With your = original >> > command, "%{time_namelookup}\n" is treated as another URL to fetch. >> > With no proxy option, curl realizes it's not an url immediately and >> > skips to the next argument on the commandline - http://www.example.com= . >> > With a proxy, curl has to send each url to the proxy for processing. >> > The proxy probably returns a "400 Bad Request" error on the first >> > (invalid) url, which is redirected to /dev/null. =C2=A0=C2=A0The next = url doesn't >> > have another -o so it falls back to printing to stdout. >> > >> > Adding -v to the curl commandline will help you diagnose problems like >> > this. >> >> Thanks for that, though it's unfortunate. >> >> I would really like a better understanding of the times, to help further >> diagnose the problem, and 'man curl' says that multiple invocations of >> '-w' will result in the last one winning, which I've verified. >> >> Do you have any suggestions for a way to get the timing of these >> operations without resorting to tcpdump? > > Does -w "%{time_total}\n%{time_namelookup}\n" not do what you want? =C2= =A0There > are a bunch of other time_* variables you could add, too. > > Also, there's nothing wrong with tcpdump (or wireshark). =C2=A0If your tr= affic > passes through multiple proxies or content-analyzing firewalls, you can r= un > multiple simultaneous tcpdumps, one on each interface. =C2=A0Then you can= run > your curl command, and compare the traces side-by-side and see if any > servers are taking longer than expected to forward the data. =C2=A0If you= have a > managed switch, you might even be able to configure a "monitor" port that > will forward all traffic it sees to that port, and you can run just one > tcpdump and see the same packet multiple times as it passes from server t= o > server. Sigh. A failure of imagination on my part. Putting multiple parameters inside a single set of quote marks works exactly as I need. Nothing wrong with wireshark/tcpdump, but I'm not nearly as competent with them as I'd like to be, and curl offers a pretty easy way to break out the timing of various parts of the conversation - in particular the name resolution vs. the rest of the conversation for any given transaction. I do indeed have monitor ports set up on my switches, and use them to feed ntop, with an occasional tcpdump capture to figure out problems. If it comes to that, I'll get those traces and work on the comparisons as you suggest. However, given what I've seen so far, I'm looking at my firewall as being the culprit, and further testing with curl should give me the [dis]confirmation I need. Thanks ever so much for your help. Greatly appreciated. Kurt