<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Policy blocking/deny huge traffic cause High CPU utilization in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182446#M56192</link>
    <description>&lt;P&gt;FYI DoS mitigation in Zone Protection uses less resources than DoS Protection policy.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2017 02:21:36 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-10-18T02:21:36Z</dc:date>
    <item>
      <title>Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181655#M56067</link>
      <description>&lt;P&gt;I have a PAN 200 at sales office, I have temp deny policy in place as I saw huge traffic (Genetec Traffic) from/to a specific destination/source.&lt;/P&gt;&lt;P&gt;But I still see High CPU causing the Firewall to Reboot and which triggered Site Down Alerts( Downstream device lost connection).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the Deny Policy for huge traffic (Number of Packets or Size of traffic) cause CPU Utilization by any means?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 05:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181655#M56067</guid>
      <dc:creator>sandeep.paul</dc:creator>
      <dc:date>2017-10-13T05:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181686#M56069</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73435"&gt;@sandeep.paul&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short, yes it does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's far less CPU consuming to block the traffic&amp;nbsp;before checking policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example with zone-protection or dos-protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 07:30:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181686#M56069</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-10-13T07:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181788#M56083</link>
      <description>Thanks Kiwi, is it documented anywhere. Please let me know if you have any link.</description>
      <pubDate>Fri, 13 Oct 2017 16:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181788#M56083</guid>
      <dc:creator>sandeep.paul</dc:creator>
      <dc:date>2017-10-13T16:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181789#M56084</link>
      <description>You mean zone protection will not have traffic going through the policy?</description>
      <pubDate>Fri, 13 Oct 2017 16:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181789#M56084</guid>
      <dc:creator>sandeep.paul</dc:creator>
      <dc:date>2017-10-13T16:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181907#M56100</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73435"&gt;@sandeep.paul&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure if it's directly documented everywhere. Just from a get go through the processing goes in different steps, so zone protection and DOS policies are monitored prior to the secuirty policies when you look at how the traffic is actually processed. The quicker you can have your firewall drop any traffic that would get denied the better from a processing standpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a large amount of traffic (lets say a DoS attack) that sits there and hammers a deny rule within your security policies, it would be much better from a processing standpoint to have that traffic get blocked by a DoS profile or a zone protection profile then actually making it to the security policy, as it has to process far fewer things in that scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 02:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/181907#M56100</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-15T02:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182446#M56192</link>
      <description>&lt;P&gt;FYI DoS mitigation in Zone Protection uses less resources than DoS Protection policy.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 02:21:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182446#M56192</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-18T02:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182506#M56209</link>
      <description>&lt;P&gt;Thanks Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's say specific IP traffic to be mitigated through Zone protection, can we do it on PA?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 09:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182506#M56209</guid>
      <dc:creator>sandeep.paul</dc:creator>
      <dc:date>2017-10-18T09:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Does Policy blocking/deny huge traffic cause High CPU utilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182538#M56216</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73435"&gt;@sandeep.paul&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can not specify IPs in Zone Protection, that would be a DoS policy configuration instead of Zone Protection policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 13:46:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-policy-blocking-deny-huge-traffic-cause-high-cpu/m-p/182538#M56216</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-18T13:46:26Z</dc:date>
    </item>
  </channel>
</rss>

