Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    High CPU usage

    Scheduled Pinned Locked Moved pfBlockerNG
    4 Posts 2 Posters 505 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mouseskowitz
      last edited by

      I'm running pfBlockerNG-devel 2.2.5_37. For several weeks now I've been seeing high CPU usage by /usr/local/sbin/lighttpd_pfb -f /var/unbound/pfb_dnsbl_lighty.conf. It's using 85%+ of one core of a Xeon D-5121 with very little traffic flowing. I'm not sure what's going on here, but this doesn't seem normal.

      1 Reply Last reply Reply Quote 0
      • M
        mouseskowitz
        last edited by

        I think I might have figured it out. Although the traffic rate was low, there were about a dozen requests per second going out to telemetry.malwarebytes.com. This was causing a DNSBL block rate of 34%. I quit out of Malwarebytes on the offending computers and the CPU usage dropped back down to levels that I would expect.

        1 Reply Last reply Reply Quote 0
        • provelsP
          provels
          last edited by provels

          @mouseskowitz
          I had the same issue. Added .malwarebytes.com to the DNSBL Whitelist. Might as well, as submission of suspicious activity back to them is part of what you're paying for.
          https://forum.netgate.com/topic/152239/pfblockerng-high-cpu/81?_=1604056473502

          Peder

          MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
          BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

          M 1 Reply Last reply Reply Quote 0
          • M
            mouseskowitz @provels
            last edited by

            @provels I'm using the free version so I don't really have any active scanning going on. I think I'll stick with just not having it running at the moment, but that's not a bad idea.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.