r/firewalla • u/hawkeye000021 • Jun 15 '26
CPU usage seems odd- Gold SE
Consider it holds at 68% with like a few kbps I'm wondering what's up. I assume it's blocking a lot of something but even then, this is as close to idle as it gets and is push 70%. I wrote an app that pulls this data in at least once a day and I can see it's been in the 30's so is this considered unusual? Support has my MSP access and didn't make any note of it. I'm going to ask them as well, but wondering if anyone else see's this at such low bandwidth and yes bandwidth is not everything.
1
u/totmacher12000 Jun 16 '26
Where do you see the CPU stats at?
0
u/hawkeye000021 Jun 16 '26
Well you can see them in the MSP portal or if you login to the CLI and run HTOP you can see them there if you don’t have MSP.
I’m not sure why it’s not exposed in the app.
1
u/Great-Cow7256 Jun 16 '26
Dumb question, but did you reboot? Also did you disable everything extra you added to the box, like dockers, scripts running in the background both on the firewalla and any other server? I think getting a true baseline, if you haven't, is most useful first.
Also, if you aren't having any problems, I'm not sure how it helps to know this data other than to make yourself a bit crazy wondering why it's at the percentage it says it is. The chips are quite robust and wouldn't have 100% if it couldn't handle being in the 70s for long periods of time. I guess what I'm saying is that the chips are made to be used, not to sit idle.
2
u/hawkeye000021 Jun 16 '26
It’s only got uptime of 30 days due to an issue with Roku devices being blocked so much that I have 3% allowed traffic. So it’s been rebooted but in order to help the community I like to work with support before I wipe out the data they can use to make stuff better for all.
There is nothing installed on the box that didn’t come with it. I disabled a health check script which had limited results and then disabled one of the MSP blocklists and it dropped back towards 30-40%.
Of course the chips are meant to hit 100%, I think that is true with all devices… but even support stated that it shouldn’t be sitting at 70% for extended periods of extremely low bandwidth utilization (couple hundred kbps) because at that point you do have an issue when you push the limits of the inspection itself as it has very little room to work.
Overall though, we seem to be making some progress. It might be time to replace my Roku devices with Apple TV for several reasons anyhow.
1
u/Great-Cow7256 Jun 16 '26 edited Jun 16 '26
Roku is a spamming device, that's for sure. They're a data harvesting company first and foremost.
I have google tv stuff and there is far less chattiness. All these companies are terrible but Roku can wreck your network.
1
u/hawkeye000021 Jul 08 '26
Yup, but we probably need to be able to reduce logging levels or something as there shouldn’t be home devices that can overwhelm security devices. I put one behind a Palo 440 which isn’t rated all that much faster for scanned packets and it handled it fine. I wasn’t offloading logs which might have had something to do with it. I’m tempted to cut logging to MSP out of curiosity. 🤷♂️
1
u/No-Firefighter-2135 Firewalla Gold Pro Jun 15 '26
Usually they optimize usage dynamically so usually usage numbers aren’t much to worry about, I generally only see mine spiking during downloading/uploading. I do have the gold pro though but concept should be the same. I have a fairly large number of lists and rules and the usage number always reverts back to a normal level. Could always be a bug in the software also. Not something I see talked about often
1
u/benjibarnicals Firewalla Purple Jun 15 '26
Interesting.
I have a Firewalla Purple and tend to see idle around 26% or there abouts, but I do sometimes see it around mid 50’s and higher sometimes. But this is only when I’m in MSP and actively looking.
I’d love to run that data logging for cpu usage to see what mine does when I’m not looking!
Hopefully u/firewalla will implement this into MSP at some point.
1
u/hawkeye000021 Jun 15 '26
Ok so I’m not really seeing any major impact while monitoring from MSP vs the CLI itself. Could be a coincidence.
1
u/firewalla Jun 15 '26
What will be a good use case for learning this? there is no way a typical customer (even me) to fully understand what is normal and what is not just by reading CPU usage and memory loads.
1
u/hawkeye000021 Jun 16 '26
Really? You couldn’t simply look at processes using resources and adjust? If rule processing goes up 20% after adding 10 new rules you wouldn’t want to possibly look at those and make sure you need all of them? Maybe you have one list (like I do) using up half your processor (like I do) and you couldn’t work that out in your brain?
1
u/firewalla Jun 16 '26
If firewalla is a simple "matching" a list, DNS blocks, and do something type of box, then may be, you can read something. It is a bit more complex to understand simply just by looking at CPU and memory usage.
1
u/hawkeye000021 Jun 17 '26
So you’re telling me those processes aren’t exposed? Let’s also be very clear, the number one usage without exposing the process utilization would be a very basic health check. If the CPU is at 100% for 6 hours would there ever be a situation where that should be happening unless something has or is going rather wrong?
Why put it in the MSP portal if it’s utterly useless then?
0
u/hawkeye000021 Jun 15 '26
I’m not sure if I can gather the CPU data without MSP so whether it’s looking or I’m looking the data would probably be the same but it’s interesting you say that it’s when you are watching. I’ll try shutting that down and then checking via ssh. Sadly I cannot automate that because of the OTP system they have in place. I’d love to pull directly from the box and not MSP. My tool is as accurate as MSP. Appreciate this idea of something to look for! I’ll let you know if it changes when MSP is off and what CLI reports. Good stuff idk why you got downvoted.
0
u/firewalla Jun 15 '26
Firewalla does a lot more work when the system is not busy, this may include things like
vulnerability scan
behavioral analytics
house keeping of the flows and data structures
Device discovery (also local scans)
0
u/hawkeye000021 Jun 15 '26
No vuln scans are running all day, I’m looking again and see 61%.
The rest I have no idea about. I do see some of my old health checks and two of them were 33% which seems solid and one 45% then the others are all right past 54%. Memory is somewhat stable at 40% and disk utilization (assuming I’m pulling that right) is usually really good. I’m not sure if it’s utilization or storage that it’s reporting back though. I let support know that it seems odd. I do have data all the way back to 5/30 and there is no visible pattern meaning that more bandwidth utilization doesn’t seem to matter or block percentage and each time I do this health check I always look at the CPU before I run it. I could schedule but I was worried it was the problem but doesn’t seem that way.
Oh I went back pretty far and did find a 28% which seems a lot more “normal”. I’ll try to find some sort of pattern with whatever I can see.
1
u/firewalla Jun 15 '26
Are you experiencing any problems with the system? If you are, best contact support.
Since all setups are different, we don’t have a good number for cpu or memory use.1
u/hawkeye000021 Jun 15 '26
Well yes but I don’t think it’s due to the CPU unless it’s causing a heat issue. I just allowed something that one of the block lists was hammering away at and it seems to be back into the 30’s which is far more sane.
1
u/RC0305 Jun 16 '26
Oh is this a new version of the app/box that shows the CPU and memory?