# HAProxy maxconn not working or maxconn exceeded

**URL:** <https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829>\
**Category:** Help!\
**Created:** [October 20, 2020, 11:18am UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829 "2020-10-20T11:18:25Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shoaib](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@Shoaib](https://discourse.haproxy.org/u/Shoaib)\
**Post date:** [October 20, 2020, 11:18am UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/1 "2020-10-20T11:18:25Z")

</div>

Hi everyone, we are running HAProxy server. Our haproxy configuration file has

global maxconn 16384  
defaults max-keep-alive-queue 300  
server varnish01 yyy.yyy.yyy.yy::80 check maxconn 1000  
server varnish01 zzz:zzz:zzz:zz::80 check maxconn 1000

Note that, zzz:zzz:zzz:zz and yyy:yyy:yyy:yy ip address

backend bk\_shop\_cluster,  
timeout queue 5s  
mode http  
balance leastconn  
server nginx01 10.10.10.215:443 ssl verify none check maxconn 50  
server nginx02 10.10.10.216:443 ssl verify none check maxconn 50

I want 50 connections create per server. But every time my maxconn is overloaded or exceeded. So it creates high CPU utilization and memory usage. How can i get rid of this problem?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 20, 2020, 11:36am UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/2 "2020-10-20T11:36:56Z")

</div>

Provide the ENTIRE configuration. Make sure you don’t use `nbproc` and that only a single instance of haproxy is running.

How do you come to the conclusion that `maxconn` is surpassed exactly?

---

<div class="post-metadata">

**Author:** ![sheikh303](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@sheikh303](https://discourse.haproxy.org/u/sheikh303)\
**Post date:** [October 20, 2020, 1:04pm UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/3 "2020-10-20T13:04:19Z")

</div>

> [@lukastribus](#):
>
> How do you come to the conclusion that `maxconn` is surpassed exactly?

Through request count in access log within 1 second.

---

<div class="post-metadata">

**Author:** ![sheikh303](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@sheikh303](https://discourse.haproxy.org/u/sheikh303)\
**Post date:** [October 20, 2020, 1:11pm UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/4 "2020-10-20T13:11:24Z")

</div>

> [@lukastribus](#):
>
> hat only a single instance of haproxy is running

This is confirmed. Only one 1 HAProxy instancee/process is running in 1 VM.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 20, 2020, 5:23pm UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/5 "2020-10-20T17:23:37Z")

</div>

> [@sheikh303](#):
>
> Through request count in access log within 1 second.

Then you are misunderstanding what `maxconn` is.

`maxconn` means the maximum concurrent connections to this server.

This has nothing to do with request per second at all.

You can have `maxconn 1` on a server and forward 1000 requests per second.

---

<div class="post-metadata">

**Author:** ![sheikh303](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@sheikh303](https://discourse.haproxy.org/u/sheikh303)\
**Post date:** [October 20, 2020, 7:15pm UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/6 "2020-10-20T19:15:20Z")

</div>

Is that case how can we ensure the concurrent requests per second to backend servers?  
Let’s say I want to allow max 100 requests/second to be landed at backend application server through HAProxy.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 20, 2020, 8:05pm UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/7 "2020-10-20T20:05:42Z")

</div>

> [@sheikh303](#):
>
> concurrent requests per second

there is no “concurrent requests per second”. Either we are talking about concurrency or we are talking about per second numbers.

> [@Shoaib](#):
>
> So it creates high CPU utilization and memory usage.

Your use-case is to limit CPU and memory usage. Then stop thinking about request per second, because that is the wrong approach to this.

You want to limit the actual number of in flight (that is - concurrent) requests, and that is what maxconn does.

You just need to think about it differently.

If haproxy only allows 50 connections, this means you can never have more than 50 requests in-flight (concurrency), and this is what helps you reduce CPU and memory usage.

The faster the server, the more request per second it will handle, but it will never exceed 50 in-flight transactions.

And this is the correct metric to limit CPU and memory on your backend servers.

Thinking about request per second numbers is wrong.

---

<div class="post-metadata">

**Author:** ![sheikh303](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@sheikh303](https://discourse.haproxy.org/u/sheikh303)\
**Post date:** [October 21, 2020, 6:05am UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/8 "2020-10-21T06:05:00Z")

</div>

> [@lukastribus](#):
>
> If haproxy only allows 50 connections, this means you can never have more than 50 requests in-flight (concurrency), and this is what helps you reduce CPU and memory usage.

is there any way to calculate the number of requests under each connections?

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [October 21, 2020, 7:25am UTC](https://discourse.haproxy.org/t/haproxy-maxconn-not-working-or-maxconn-exceeded/5829/9 "2020-10-21T07:25:44Z")

</div>

The amount of concurrent requests is equivalent to the maxconn value.

The amount of requests or transactions per second depends on the duration of a transaction. Once you know that, it’s just basic math.
