Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cem82
Contributor
Jump to solution

Anti bot CPU increase

Hi

After enabling anti bot blade we are observing a 10-15% baseline increase in load across all CPU fw_worker cores which is unexpected since it's essentially just IP / domain / URL reputation lookup not any sort of inspection. As soon as we disabled it, it dropped down again.  When looking at top there was no increase in rad process CPU utilisation.

I have had a look at sk98348 AB section. Since it appears to just be a reputation lookup, how does the performance impact section of the threat prevention profile fit into it? Makes sense for IPS and others but am wondering specifically for AB so that we can put at appropriate level to minimise performance impact.

I'd also like to understand more the section saying to avoid using 'any' in src or destination for antibot specifically. Does having some value in there eg a group of all our networks have same impact as 'any' so simply having something in there make a difference?

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

What about the DNS servers that internal users reference, is it also on the other side of the Firewall?

Note the same SK you reference above talks to the configuration of exceptions, refer also:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics...

sk92515: How to configure Threat Prevention Exceptions 

CCSM R77/R80/ELITE

View solution in original post

0 Kudos
4 Replies
Chris_Atkinson
Employee Employee
Employee

How is the Gateway deployed relative to the location of the DNS servers used in the environment by internal clients?

The protected scope and configuration of exceptions (e.g. internal domains) will be relative to the above amongst other considerations.

CCSM R77/R80/ELITE
0 Kudos
cem82
Contributor

Hi Chris

Currently the GW is using google DNS (oversight) so we will be changing that to our own internal recursive DNS servers.  When you say list of internal domains DNS exceptions, I can't see anywhere to configure those?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

What about the DNS servers that internal users reference, is it also on the other side of the Firewall?

Note the same SK you reference above talks to the configuration of exceptions, refer also:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics...

sk92515: How to configure Threat Prevention Exceptions 

CCSM R77/R80/ELITE
0 Kudos
Chris_Atkinson
Employee Employee
Employee

An uptick in CPU utilization is expected, how much is relative to the configuration / traffic.

For reference below is an example of the Performance attribute for specific Anti-bot protections

In addition to reputation, some are signatures (as below) and others are behavioral.

Security Policy > Threat Prevention Policy > Custom Policy Tools > Protections  

Performance.png

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events