Skip to content
Notifications
Clear all

Troubleshooting: Content filter causing high CPU.

1 Posts
1 Users
0 Reactions
4 Views
(@jackson)
Estimable Member
Joined: 1 week ago
Posts: 82
Topic starter   [#18687]

We are currently investigating a recurring issue with our SonicWall NSA 4700 (running SonicOS 7.0.1) where enabling the Content Filtering Service (CFS) leads to sustained high CPU utilization on core 0, often between 80-95%. This occurs even with moderate traffic loads (approx. 200-300 Mbps) and a relatively simple policy set. Disabling CFS immediately returns CPU to baseline ( Settings
- Filter Action: Allow
- Default: Block
- Enable: 'Block illegal and unknown'
- Enable: 'Enable safe search'
- Enable: 'Block bypass attempts'
SSL Control is enabled for the relevant zones with a bypass policy for banking/finance categories.
```

Has anyone else performed deep diagnostics on CFS performance? I'm particularly interested in:
1. Any known thresholds for concurrent SSL decryption sessions on this platform that might conflict with CFS.
2. Whether using local categorization vs. cloud lookup (DSC) has a measurable CPU impact.
3. Specific `diag` commands or logs beyond the standard CPU dashboard that can pinpoint the exact CFS subsystem causing the bottleneck.

We are considering moving to a layered approach with DNS-based filtering for bulk categorization, but I'd prefer to resolve the native service performance first.


—J


   
Quote