Hi everyone,
One of our branches has an 1800 R81.10.08 (996001683) centrally managed by a SMS R81.20 which most of time has 100% cpu usage, blades that are enabled:
- Firewall
- Vpn S2S
- Antivirus
- Identity Awareness
- Application Control
- Https Inspection
Within VPN we share domain services (VoIP, AD, Printing) in order to connect to other branches and main office.
We recently enabled HTTPS because some pages weren't working OK, we've been monitoring load usage on appliance and has been almost at 100% cpu usage.
Our HTTPS rulebase bypasses some categories as recommended (financial, business, etc.), internal traffic and some custom application/sites.
When monitoring with top and cpview, shows that multiple wstlsd processes are consuming most of CPU.
Investigated further with fw ctl multik print_heavy_conn and found that most of connections were going to Office 365 services, we added a rule to accept this traffic at fw layer and still shows it the same.
At deactivating HTTPS, concurrent connections reduce in > 50% of hosts.
We tested on site and found no issues at all,
This branch has 200 hosts average, and we want to know how can we low cpu usage and if a better equipment is required?