We are currently investigating a recurring issue with our SonicWall NSA 4700 (running SonicOS 7.0.1) where enabling the Content Filtering Service (CFS) leads to sustained high CPU utilization on core 0, often between 80-95%. This occurs even with moderate traffic loads (approx. 200-300 Mbps) and a relatively simple policy set. Disabling CFS immediately returns CPU to baseline ( Settings
- Filter Action: Allow
- Default: Block
- Enable: 'Block illegal and unknown'
- Enable: 'Enable safe search'
- Enable: 'Block bypass attempts'
SSL Control is enabled for the relevant zones with a bypass policy for banking/finance categories.
```
Has anyone else performed deep diagnostics on CFS performance? I'm particularly interested in:
1. Any known thresholds for concurrent SSL decryption sessions on this platform that might conflict with CFS.
2. Whether using local categorization vs. cloud lookup (DSC) has a measurable CPU impact.
3. Specific `diag` commands or logs beyond the standard CPU dashboard that can pinpoint the exact CFS subsystem causing the bottleneck.
We are considering moving to a layered approach with DNS-based filtering for bulk categorization, but I'd prefer to resolve the native service performance first.
—J