Hi
After enabling anti bot blade we are observing a 10-15% baseline increase in load across all CPU fw_worker cores which is unexpected since it's essentially just IP / domain / URL reputation lookup not any sort of inspection. As soon as we disabled it, it dropped down again. When looking at top there was no increase in rad process CPU utilisation.
I have had a look at sk98348 AB section. Since it appears to just be a reputation lookup, how does the performance impact section of the threat prevention profile fit into it? Makes sense for IPS and others but am wondering specifically for AB so that we can put at appropriate level to minimise performance impact.
I'd also like to understand more the section saying to avoid using 'any' in src or destination for antibot specifically. Does having some value in there eg a group of all our networks have same impact as 'any' so simply having something in there make a difference?