<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP DNS utilise the most CPU and concurrent connection in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199767#M33368</link>
    <description>&lt;P&gt;Ah for Load Sharing you won't want to turn off sync of DNS in the event of asymmetry through the cluster, I assumed you were using HA.&amp;nbsp; My bad.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 14:53:09 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-12-05T14:53:09Z</dc:date>
    <item>
      <title>UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199549#M33331</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm not sure if this is normal or not. but as of today we are troubleshooting one of our customer firewall and we notice that UDP DNS is taking up most of the CPU processing and from almost 200K+- concurrent connections 180K+ is being used by UDP. Looking for some comment and suggestion from all the masters. We are currently doing some checking on what is causing the memory to utilize almost 70%. the appliance is using 6700 with 32GB of RAM installed inside the appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-12-03 at 10.02.30 AM.png" style="width: 444px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23503iE5471B3D5E7DF5A9/image-dimensions/444x326?v=v2" width="444" height="326" role="button" title="Screenshot 2023-12-03 at 10.02.30 AM.png" alt="Screenshot 2023-12-03 at 10.02.30 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-12-03 at 10.08.53 AM.png" style="width: 290px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23504i24B82FECBCCC2FAB/image-dimensions/290x336?v=v2" width="290" height="336" role="button" title="Screenshot 2023-12-03 at 10.08.53 AM.png" alt="Screenshot 2023-12-03 at 10.08.53 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Free -h&lt;/P&gt;&lt;P&gt;total used free shared buff/cache available&lt;BR /&gt;Mem: 31G 10G 5.3G 10G 15G 8.4G&lt;BR /&gt;Swap: 31G 3.0M 31G&lt;/P&gt;&lt;P&gt;fw ctl pstat&lt;/P&gt;&lt;P&gt;Virtual System Capacity Summary:&lt;BR /&gt;Physical memory used: 73% (19813 MB out of 27113 MB) - below watermark&lt;BR /&gt;Kernel memory used: 9% (2501 MB out of 27113 MB) - below watermark&lt;BR /&gt;Virtual memory used: 63% (17217 MB out of 27113 MB) - below watermark&lt;BR /&gt;Used: 17217 MB by FW, 36414 MB by zeco&lt;BR /&gt;Concurrent Connections: 197791 (Unlimited)&lt;BR /&gt;Aggressive Aging is enabled, not active&lt;/P&gt;&lt;P&gt;Kernel memory (kmem) statistics:&lt;BR /&gt;Total memory bytes used: 4064425705 peak: 17248058149&lt;BR /&gt;Allocations: 2378340323 alloc, 0 failed alloc&lt;BR /&gt;2235864245 free, 0 failed free&lt;/P&gt;&lt;P&gt;Cookies:&lt;BR /&gt;3511454616 total, 89080 alloc, 89080 free,&lt;BR /&gt;2167360 dup, 2206143026 get, 1969436521 put,&lt;BR /&gt;1807612677 len, 95659764 cached len, 23567 chain alloc,&lt;BR /&gt;23567 chain free&lt;/P&gt;&lt;P&gt;Connections:&lt;BR /&gt;981379508 total, 11899190 TCP, 964579454 UDP, 4900744 ICMP,&lt;BR /&gt;120 other, 456 anticipated, 24810 recovered, 197797 concurrent,&lt;BR /&gt;2034871 peak concurrent&lt;/P&gt;&lt;P&gt;Fragments:&lt;BR /&gt;560707 fragments, 276569 packets, 12 expired, 0 short,&lt;BR /&gt;0 large, 0 duplicates, 0 failures&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;305076803/0 forw, 309191099/0 bckw, 1318730867 tcpudp,&lt;BR /&gt;4044131 icmp, 552888828-967582277 alloc&lt;/P&gt;&lt;P&gt;Sync: Run "cphaprob syncstat" for cluster sync statistics.&lt;/P&gt;&lt;P&gt;currently only below blades are enabled.&lt;/P&gt;&lt;P&gt;Firewall, IPSec VPN, Mobile Access.&lt;/P&gt;&lt;P&gt;Firewall version is R81.20 with HFA 26&lt;/P&gt;&lt;P&gt;Any suggestion&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 02:21:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199549#M33331</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-03T02:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199677#M33353</link>
      <description>&lt;P&gt;If Mobile Access is enabled and serving clients, that could be the reason.&lt;BR /&gt;If your clients have to traverse the gateway to reach the DNS server, that could also cause this problem.&lt;/P&gt;
&lt;P&gt;What are the exact symptoms you're concerned with?&lt;BR /&gt;That amount of memory utilization isn't unusual and is likely due to caching.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 21:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199677#M33353</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-04T21:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199694#M33355</link>
      <description>&lt;P&gt;Do you allow DNS traffic to source / destination any in your security policy?&lt;/P&gt;
&lt;P&gt;Which version is this and do you have DNS tunneling protections enabled (Anti-bot, IPS etc)?&lt;/P&gt;
&lt;P&gt;See also Tip 7 here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Connection-Table/td-p/41581" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Connection-Table/td-p/41581&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 00:31:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199694#M33355</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-05T00:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199695#M33356</link>
      <description>&lt;P&gt;Hi Admin,&lt;/P&gt;&lt;P&gt;the usage for mobile access is not so heavy as it is only being use by us to access our customer network. roughly less then 5 users are active.&lt;/P&gt;&lt;P&gt;Basically, we just upgrade the firewall from R81.10 to R81.20. Previously when using R81.10. the firewall memory are only utilizing around 60% and went down when the traffic is low. However, after upgrade to R81.20 we notice that the firewall memory being utilize up to 90%+ and most of the time cause traffic drop. and i notice that UDP traffic is taking most of the utilizations. that is why i'm asking if it is normal to see UDP traffic that high.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 00:55:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199695#M33356</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-05T00:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199696#M33357</link>
      <description>&lt;P&gt;Yes, we do have that. currently we enable firewall and mobile access. we plan to enable IPS but since the memory is not stable we disable it first.&lt;/P&gt;&lt;P&gt;i will try and see if your suggestion works for my environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 00:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199696#M33357</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-05T00:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199697#M33358</link>
      <description>&lt;P&gt;Recommend also restricting the rules allowing DNS traffic so it is less broad in that case.&lt;/P&gt;
&lt;P&gt;I assume that there is an internal DNS server that users should be querying rather than external/public.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 01:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199697#M33358</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-05T01:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199701#M33359</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;i follow the tip 7 just now and can see concurrent connection drop from 180K to 80K. cpu utilization also coming down now. still monitoring the situation first. yes, our customer do have internal DNS server to query outside. but they also allow internal to query specific external DNS server. just not sure why during using R81.10 this issue does not arise. Only see this when upgrade to R81.20.&lt;/P&gt;&lt;P&gt;thanks for the recommendation.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 03:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199701#M33359</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-05T03:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199740#M33364</link>
      <description>&lt;P&gt;If you have a cluster, you may also want to consider turning off state synchronization for whatever service you are using to match UDP/53 traffic (usually domain-udp), as this will save quite a bit of CPU resources (and a bit of memory) no longer trying to sync the rapid-fire, short-lived DNS recursive lookups.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 12:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199740#M33364</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-05T12:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199763#M33367</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;i try to do that just now. but it seems like the DNS server are not able to fully query domain name. there are certain domains that are not cache giving error. after re-enabling it back it seems like back to normal. currently i'm using Load Sharing unicast.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:40:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199763#M33367</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-05T14:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199767#M33368</link>
      <description>&lt;P&gt;Ah for Load Sharing you won't want to turn off sync of DNS in the event of asymmetry through the cluster, I assumed you were using HA.&amp;nbsp; My bad.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199767#M33368</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-05T14:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: UDP DNS utilise the most CPU and concurrent connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199814#M33376</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;yes, that is what i'm thinking. no problem. it is a good suggestion. i can use it if using HA after this. previously it is running on HA mode.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 23:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UDP-DNS-utilise-the-most-CPU-and-concurrent-connection/m-p/199814#M33376</guid>
      <dc:creator>Abeja_huhuhu</dc:creator>
      <dc:date>2023-12-05T23:14:14Z</dc:date>
    </item>
  </channel>
</rss>

