Scalability issue when using outgoing asynchronous web requests on IIS 7.5(在 IIS 7.5 上使用传出异步 Web 请求时的可伸缩性问题)

UPDATE 19/2, 2013: We have cleared some question marks in this and I have a theory of what the main problem is which I'll update below. Not ready to write a "solved" response to it yet though.

UPDATE 24/4, 2013: Things have been stable in production (though I believe it is temporary) for a while now and I think it is due to two reasons. 1) port increase, and 2) reduced number of outgoing (forwarded) requests. I'll continue this update futher down in the correct context.

We are currently doing an investigation in our production environment to determine why our IIS web server does not scale when too many outgoing asynchronous web service requests are being done (one incoming request may trigger multiple outgoing requests).

CPU is only at 20%, but we receive HTTP 503 errors on incoming requests and many outgoing web requests get the following exception: "SocketException: An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full" Clearly there is a scalability bottleneck somewhere and we need to find out what it is and if it is possible to solve it by configuration.


We are running IIS v7.5 integrated managed pipeline using .NET 4.5 on Windows 2008 R2 64 bit operating system. We use only 1 worker process in IIS. Hardware varies slightly but the machine used for examining the error is an Intel Xeon 8 core (16 hyper threaded).

We use both asynchronous and synchronous web requests. Those that are asynchronous are using the new .NET async support to make each incoming request make multiple HTTP requests in the application to other servers on persisted TCP connections (keep-alive). Synchronous request execution time is low 0-32 ms (longer times occur due to thread context switching). For the asynchronous requests, execution time can be up to 120 ms before the requests are aborted.

Normally each server serves up to ~1000 incoming requests. Outgoing requests are ~300 requests/sec up to ~600 requests/sec when problem starts to arise. Problems only occurs when outgoing async. requests are enabled on the server and we go above a certain level of outgoing requests (~600 req./s).


Searching the Internet on this problem reveals a plethora of possible solutions candidates. Though, they are very much dependent upon versions of .NET, IIS and operating system so it takes time to find something in our context (anno 2013).


Below is a list of solution candidates and the conclusions we have come to so far with regards to our configuration context. I have categorised the detected problem areas, so far in the following main categories:

  1. Some queue(s) fill up
  2. Problems with TCP connections and ports (UPDATE 19/2, 2013: This is the problem)
  3. Too slow allocation of resources
  4. Memory problems (UPDATE 19/2, 2013: This is most likely another problem)

1) Some queue(s) fill up

The outgoing asynchronous request exception message does indicate that some queue of buffer has been filled up. But it does not say which queue/buffer. Via the IIS forum (and blog post referenced there) I have been able to distinguish 4 of possibly 6 (or more) different types of queues in the request pipeline labeled A-F below.

Though it should be stated that of all the below defined queues, we see for certain that the 1.B) ThreadPool performance counter Requests Queued gets very full during the problematic load. So it is likely that the cause of the problem is in .NET level and not below this (C-F).

We use the .NET framework class WebClient for issuing the asynchronous call (async support) as opposed to the HttpClient that we experienced had the same issue but with far lower req/s threshold. We do not know if the .NET Framework implementation hides any internal queue(s) or not above the Thread pool. We don’t think this is the case.

The Thread pool acts as a natural queue since the .NET Thread (default) Scheduler is picking threads from the thread pool to be executed.

Performance counter: [ASP.NET v4.0.30319].[Requests Queued].


  1. (ApplicationPool) maxConcurrentRequestsPerCPU should be 5000 (instead of previous 12). So in our case it should be 5000*16=80.000 requests/sec which should be sufficient enough in our scenario.
  2. (processModel) autoConfig = true/false which allows some threadPool related configuration to be set according to machine configuration. We use true which is a potential error candidate since these values may be set erroneously for our (high) need.

1.C) Global, process wide, native queue (IIS integrated mode only)

If the Thread Pool is full, requests starts to pile up in this native (not-managed) queue.

Performance counter:[ASP.NET v4.0.30319].[Requests in Native Queue]

This queue is not the same queue as 1.C) above. Here’s an explanation as stated to me "The HTTP.sys kernel queue is essentially a completion port on which user-mode (IIS) receives requests from kernel-mode (HTTP.sys). It has a queue limit, and when that is exceeded you will receive a 503 status code. The HTTPErr log will also indicate that this happened by logging a 503 status and QueueFull".

Performance counter: I have not been able to find any performance counter for this queue, but by enabling the IIS HTTPErr log, it should be possible to detect if this queue gets flooded.

Configuration possibilities: This is set in IIS on the application pool, advanced setting: Queue Length. Default value is 1000. I have seen recommendations to increase it to 10.000. Though trying this increase has not solved our issue.

Although unlikely, I guess the OS could actually have a queue somewhere in between the network card buffer and the HTTP.sys queue.


As request arrive to the network card, it should be natural that they are placed in some buffer in order to be picked up by some OS kernel thread. Since this is kernel level execution, and thus fast, it is not likely that it is the culprit.

Windows Performance Counter: [Network Interface].[Packets Received Discarded] using the network card instance.

This is a candidate that pops up here and there, though our outgoing (async) TCP requests are made of a persisted (keep-alive) TCP connection. So as the traffic grows, the number of available ephemeral ports should really only grow due to the incoming requests. And we know for sure that the problem only arises when we have outgoing requests enabled.

However, the problem may still arise due to that the port is allocated during a longer timeframe of the request. An outgoing request may take as long as 120 ms to execute (before the .NET Task (thread) is canceled) which might mean that the number of ports get allocated for a longer time period. Analyzing the Windows Performance Counter, verifies this assumption since the number of TCPv4.[Connection Established] goes from normal 2-3000 to peaks up to almost 12.000 in total when the problem occur.

We have verified that the configured maximum amount of TCP connections is set to the default of 16384. In this case, it may not be the problem, although we are dangerously close to the max limit.

When we try using netstat on the server it mostly returns without any output at all, also using TcpView shows very few items in the beginning. If we let TcpView run for a while it soon starts to show new (incoming) connections quite rapidly (say 25 connections/sec). Almost all connections are in TIME_WAIT state from the beginning, suggesting that they have already completed and waiting for clean up. Do those connections use ephemeral ports? The local port is always 80, and the remote port is increasing. We wanted to use TcpView in order to see the outgoing connections, but we can’t see them listed at all, which is very strange. Can’t these two tools handle the amount of connections we are having? (To be continued.... But please fill in with info if you know it… )

Furhter more, as a side kick here. It was suggested in this blog post "ASP.NET Thread Usage on IIS 7.5, IIS 7.0, and IIS 6.0" that ServicePointManager.DefaultConnectionLimit should be set to int maxValue which otherwise could be a problem. But in .NET 4.5, this is the default already from the start.

  1. 可以合理地假设我们确实达到了 16.384 个端口的最大限制.我们将除一台服务器以外的所有服务器上的端口数量增加了一倍,当我们达到旧的传出请求峰值负载时,只有旧服务器会遇到问题.那么为什么 TCP.v4.[已建立的连接] 在出现问题时从未向我们显示高于 ~12.000 的数字?我的理论:很可能,尽管尚未确定为事实(尚未),性能计数器 TCPv4.[已建立的连接] 不等于当前分配的端口数.我还没有时间学习 TCP 状态,但我猜测 TCP 状态比已建立连接"显示的更多,这会使端口被占用.虽然我们不能使用连接建立"性能计数器来检测端口用完的危险,但重要的是我们找到其他方法来检测何时达到此最大端口范围.如上文所述,我们无法在生产服务器上使用 NetStat 或应用程序 TCPview 来实现此目的.这是个问题!(我会在我认为这篇文章的后续回复中写更多关于它的信息)
  2. Windows 上的端口数限制为最大 65.535(尽管可能不应该使用前约 1000 个).但是应该可以通过减少 TCP 状态 TIME_WAIT 的时间(默认为 24​​0 秒)来避免端口耗尽的问题,如许多地方所述.它应该更快地释放端口.我首先对此有点犹豫,因为我们同时使用长时间运行的数据库查询以及 TCP 上的 WCF 调用,我不想减少时间限制.虽然还没有赶上我的 TCP 状态机读取,但我认为它毕竟可能不是问题.我认为,状态 TIME_WAIT 只是为了允许与客户端正确关闭握手.因此,现有 TCP 连接上的实际数据传输不应由于此时间限制而超时.更糟糕的情况是,客户端没有正确关闭,而是需要超时.我猜所有的浏览器可能都没有正确实现这一点,它可能只是客户端的问题.虽然我在这里猜测了一下......

2013 年 4 月 24 日更新:我们已将端口数增加到最大值.同时,我们没有像以前那样收到那么多转发的传出请求.这两者结合起来应该是我们没有发生任何事件的原因.但是,这只是暂时的,因为将来这些服务器上的传出请求数量肯定会再次增加.因此,我认为问题在于,传入请求的端口必须在响应转发请求的时间范围内保持打开状态.在我们的应用程序中,这些转发请求的取消限制为 120 毫秒,可以与处理未转发请求的正常 <1 毫秒进行比较.所以本质上,我相信端口的确定数量是我们正在使用的高吞吐量服务器(在约 16 核机器上 > 1000 个请求/秒)的主要可扩展性瓶颈.这与缓存重新加载(见下文)的 GC 工作相结合,使服务器特别容易受到攻击.

UPDATE 24/4, 2013: We have increased the number of port to to the maximum value. At the same time we do not get as many forwarded outgoing requests as earlier. These two in combination should be the reason why we have not had any incidents. However, it is only temporary since the number of outgoing requests are bound to increase again in the future on these servers. The problem thus lies in, I think, that port for the incoming requests has to remain open during the time frame for the response of the forwarded requests. In our application, this cancelation limit for these forwarded requests is 120 ms which could be compared with the normal <1ms to handle a non forwarded request. So in essence, I believe the definite number of ports is the major scalability bottleneck on such high throughput servers (>1000 requests/sec on ~16 cores machines) that we are using. This in combination with the GC work on cache reload (se below) makes the server especially vulernable.

Our performance counters show that the number of queued requests in the Thread Pool (1B) fluctuates a lot during the time of the problem. So potentially this means that we have a dynamic situation in which the queue length starts to oscillate due to changes in the environment. For instance, this would be the case if there are flooding protection mechanisms that are activated when traffic is flooding. As it is, we have a number of these mechanisms:

When things go really bad and the server responds with a HTTP 503 error, the load balancer will automatically remove the web server from being active in production for a 15 second period. This means that the other servers will take the increased load during the time frame. During the "cooling period", the server may finish serving its request and it will automatically be reinstated when the load balancer does its next ping. Of course this only is good as long as all servers don’t have a problem at once. Luckily, so far, we have not been in this situation.

In the web application, we have our own constructed valve (Yes. It is a "valve". Not a "value") triggered by a Windows Performance Counter for Queued Requests in the thread pool. There is a thread, started in Application_Start, that checks this performance counter value each second. And if the value exceeds 2000, all outgoing traffic ceases to be initiated. The next second, if the queue value is below 2000, outgoing traffic starts again.

The strange thing here is that it has not helped us from reaching the error scenario since we don’t have much logging of this occurring. It may mean that when traffic hits us hard, things goes bad really quickly so that the 1 second time interval check actually is too high.

There is another aspect of this as well. When there is a need for more threads in the application pool, these threads gets allocated very slowly. From what I read, 1-2 threads per second. This is so because it is expensive to create threads and since you don’t want too many threads anyways in order to avoid expensive context switching in the synchronous case, I think this is natural. However, it should also mean that if a sudden large burst of traffic hits us, the number of threads are not going to be near enough to satisfy the need in the asynchronous scenario and queuing of requests will start. This is a very likely problem candidate I think. One candidate solution may be then to increase the minimum amount of created threads in the ThreadPool. But I guess this may also effect performance of the synchronously running requests.

(Joey Reyes wrote about this here in a blog post) Since objects get collected later for asynchronous requests (up to 120ms later in our case), memory problem can arise since objects can be promoted to generation 1 and the memory will not be recollected as often as it should. The increased pressure on the Garbage Collector may very well cause extended thread context switching to occur and further weaken capacity of the server.

However, we don’t see an increased GC- nor CPU usage during the time of the problem so we don’t think the suggested CPU throttling mechanism is a solution for us.

UPDATE 19/2, 2013: We use a cache swap mechanism at regular intervalls at which an (almost) full in-memory cache is reload into memory and the old cache can get garbage collected. At these times, the GC will have to work harder and steal resources from the normal request handling. Using Windows Performance counter for thread context switching it shows that the number of context switches decreases significantly from the normal high value at the time of a high GC usage. I think that during such cache reloads, the server is extra vulnernable for queueing up requests and it is necessary to reduce the footprint of the GC. One potential fix to the problem would be to just fill the cache without allocating memory all the time. A bit more work, but it should be doable.

2013 年 4 月 24 日更新:我仍在缓存重新加载内存调整的中间,以避免让 GC 运行太多.但是当 GC 运行时,我们通常会暂时有大约 1000 个排队请求.由于它在所有线程上运行,它自然会从正常的请求处理中窃取资源.部署此调整后,我将更新此状态,我们可以看到不同之处.

UPDATE 24/4, 2013: I am still in the middle of the cache reload memory tweak in order to avoid having the GC running as much. But we normally have some 1000 queued requests temporarily when the GC runs. Since it runs on all threads, it is naturall that it steals resources from the normal requests handling. I'll update this status once this tweak has been deployed and we can see a difference.

我已经通过 Async Http Handler 实现了一个反向代理,用于基准测试(作为我博士论文的一部分)并且遇到了和你一样的问题.

I have implemented a reverse proxy through an Async Http Handler for benchmarking purposes (as a part of my Phd. Thesis) and run into the very same problems as you.

为了扩展,必须将 processModel 设置为 false 并微调线程池.我发现,与有关 processModel 默认值的文档所说的相反,当 processModel 设置为 true 时,许多线程池没有正确配置.maxConnection 设置也很重要,因为如果限制设置得太低,它会限制您的可伸缩性.请参阅 http://support.microsoft.com/default.aspx?scid=kb;en-us;821268

In order to scale it is mandatory to have processModel set to false and fine tune the thread pools. I have found that, contrary to what the documentation regarding processModel defaults says, many of the thread pools are not properly configured when processModel is set to true. The maxConnection setting it is also important as it limits your scalability if the limit is set too low. See http://support.microsoft.com/default.aspx?scid=kb;en-us;821268

关于由于套接字上的 TIME_WAIT 延迟而导致您的应用程序耗尽端口的问题,我也遇到了同样的问题,因为我在 240 秒内从有限的一组机器中注入了超过 64k 个请求的流量.我将 TIME_WAIT 降低到 30 秒没有任何问题.

Regarding your app running out of ports because of the TIME_WAIT delay on the socket, I have also faced the same problem because I was injecting traffic from a limited set of machines with more than 64k requests in 240 seconds. I lowered the TIME_WAIT to 30 seconds without any problems.

我还错误地将代理对象重用到多个线程中的 Web 服务端点.虽然代理没有任何状态,但我发现 GC 在收集与其内部缓冲区(String [] 实例)相关的内存时遇到了很多问题,这导致我的应用程序内存不足.

I also mistakenly reused a proxy object to a Web Services endpoint in several threads. Although the proxy doesn't have any state, I found that the GC had a lot of problems collecting the memory associated with its internal buffers (String [] instances) and that caused my app to run out of memory.

您应该监控的一些有趣的性能计数器是与 ASP.NET 应用程序类别下的排队请求、执行中的请求和请求时间相关的那些.如果您看到排队的请求或执行时间很短但客户端看到很长的请求时间,那么您的服务器中存在某种争用.还监视 LocksAndThreads 类别下的计数器以查找争用.

Some interesting performance counters that you should monitor are the ones related to Queued requests, requests in execution and request time under the ASP.NET apps category. If you see queued requests or that the execution time is low but the clients see long request times, then you have some sort of contention in your server. Also monitor counters under the LocksAndThreads category looking for contention.

