- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-05-2019 06:16 AM
Hi there,
Quick question. I'm currently troubleshooting a PA 3020 in version 8.0.12 for one of my customer. Its PA has huge DP CPU usage (arround 80%). I try to figure out the reason of this usage.
I've isolated the "ctd_token" process which is a big CPU user. Can you give me a hint about its utility?
cheers,
Edouard
06-05-2019 08:40 PM
so how much cpu process is used by this process?
any other process has high cpu usage?
do you have ssl decryption enabled?
06-13-2019 12:37 AM - edited 06-13-2019 12:38 AM
Support explained me the meaning of this process:
"The tokens are for decoder regex matches , so check to see if they have a lot of custom signatures defined via regex. do you using a lot of custom signature? "
=> There is no custom sig.
Then they reply :
"CTD ( content detection) and To reduce the cpu overload used by the content detector, application override need to be configured for the above applications.
you need to double check the acc logs and see the top 3 application used during the high dp load and create the application override for those application."
06-13-2019 08:42 AM
Hello,
While App override does reduce the DP CPU usage, it is because it bypasses Content inspection so the data is identified and 'trusted' and not scanned for malicious payloads.
Use sparingly!
Regards,
06-13-2019 10:49 AM
agree it is not safe to use app override under these scenarios.
06-13-2019 10:51 AM
This is not good idea to use the app override to reduce the DP load
are you hitting the capacity issues on current PA?
upgrading the hardware is safer option i think but it depends on your company also?
are you doing ssl decryption?
what is your max session count?
06-14-2019 01:39 AM
Hi, I agree, override will be a temporary solution. We explained the customer he has to upgrade the box (no ssl decryption). The box is just hitting its capabilities. Thanks all and have a good day.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!