CPU issue after adding thread feed
Hello,
After we added 8 different new “Domain Name Threat Feed” as External Connector to our FW device and activated it, the device CPU reached 99-100% in a short time and the systems became inoperable and could not be operated from the interface. Is this an expected situation, do you have any suggestions to prevent this from happening again, what can be done for CPU-based interface access problem?
Below is the list of 8 added;
Threat Intelligence Feeds DNS Blocklist - mini version https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/tif.mini.txt
Threat Intelligence Feeds DNS Blocklist - mini version only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/tif.mini-onlydomains.txt
Fake DNS Blocklist https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/fake.txt
Fake DNS Blocklist only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/fake-onlydomains.txt
Encrypted DNS/VPN/TOR/Proxy Bypass DNS Blocklist https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/doh-vpn-proxy-bypass.txt
Encrypted DNS/VPN/TOR/Proxy Bypass DNS Blocklist only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/doh-vpn-proxy-bypass-onlydomains.txt
Light DNS Blocklist https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/light.txt
Light DNS Blocklist only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/light-onlydomains.txt
Best Regards, İsmail Ürek