84 % ( 6888/8131 MB ) { ARC size 5670 MB }
root@sense:/var/log # top last pid: 958; load averages: 2.79, 2.46, 2.30 up 1+07:46:53 04:34:2464 processes: 2 running, 62 sleepingCPU: 21.6% user, 0.0% nice, 19.9% system, 1.1% interrupt, 57.5% idleMem: 144M Active, 651M Inact, 4724K Laundry, 1254M Wired, 2056K Buf, 5839M FreeARC: 639M Total, 29M MFU, 540M MRU, 7511K Anon, 3027K Header, 59M Other 513M Compressed, 563M Uncompressed, 1.10:1 RatioSwap: 8418M Total, 8418M Free PID USERNAME THR PRI NICE SIZE RES STATE C TIME WCPU COMMAND69587 root 12 20 0 869M 213M uwait 3 8:51 4.62% AdGuardHome31921 root 8 22 0 182M 106M kqread 2 0:03 0.00% python3.956389 root 7 20 0 176M 114M nanslp 3 33:54 2.85% suricata30363 unbound 4 20 0 111M 41M kqread 1 0:01 0.00% unbound 256 root 1 52 0 109M 58M accept 3 17:15 0.89% python3.9 8197 root 1 20 0 58M 32M accept 3 0:04 1.51% php-cgi28719 root 1 52 0 58M 31M accept 0 0:04 0.00% php-cgi93364 root 1 52 0 58M 30M accept 1 0:02 0.00% php-cgi89757 root 1 52 0 58M 29M accept 3 0:00 0.50% php-cgi91927 root 1 52 0 58M 29M accept 0 0:00 0.00% php-cgi 4396 root 6 21 0 54M 14M kqread 0 18.2H 56.32% syslog-ng17222 root 1 20 0 54M 24M wait 2 0:01 0.00% php-cgi75764 root 1 52 0 52M 31M accept 2 0:06 0.00% php-cgi17186 root 1 20 0 48M 24M wait 1 0:00 0.00% php-cgi65908 root 1 20 0 48M 30M select 1 555:06 0.01% python3.968422 root 1 20 0 39M 28M nanslp 0 0:10 0.00% perl 7733 dhcpd 1 20 0 25M 11M select 0 0:00 0.00% dhcpd 252 root 1 52 0 24M 13M wait 2 0:03 0.00% python3.982663 root 1 20 0 23M 12M select 1 0:03 0.03% python3.982649 root 1 20 0 23M 12M select 1 0:03 0.03% python3.925582 dhcpd 1 20 0 22M 9312K select 1 0:07 0.00% dhcpd 4259 root 1 52 0 21M 8032K wait 1 0:00 0.00% syslog-ng89560 root 1 20 0 21M 6804K select 3 0:27 0.03% ntpd17086 root 1 20 0 21M 9908K kqread 2 6:58 0.07% lighttpd64380 root 2 20 0 18M 6432K nanslp 2 0:05 0.00% monit17051 cyprien 1 20 0 18M 7872K select 1 0:00 0.02% sshd14639 root 1 21 0 18M 7568K select 2 0:00 0.00% sshd16122 root 1 20 0 18M 6748K select 3 0:00 0.00% sshd53597 vnstat 1 20 0 15M 5168K nanslp 3 0:12 0.00% vnstatd66413 root 1 25 0 14M 4020K piperd 2 3:33 0.30% bash90011 root 1 20 0 14M 3996K CPU2 2 0:00 0.14% top94261 root 1 20 0 14M 4048K kqread 3 0:01 0.00% lighttpd54965 root 1 20 0 13M 3852K pause 0 0:00 0.00% csh97710 root 1 24 0 13M 2944K wait 1 0:36 0.01% sh17058 cyprien 1 20 0 13M 3428K wait 0 0:00 0.00% sh51767 root 1 52 0 13M 3196K wait 3 0:00 0.00% sh25912 root 1 20 0 13M 3056K wait 3 0:01 0.00% sh45202 cyprien 1 24 0 13M 2948K wait 3 0:00 0.00% su91245 _dhcp 1 20 0 13M 2792K select 1 0:06 0.02% dhclient85398 root 1 4 0 13M 2744K select 3 0:00 0.00% dhclient85031 root 1 20 0 13M 2664K select 0 0:00 0.01% dhclient33799 root 1 87 0 13M 3220K CPU3 3 310:17 52.26% filterlog91867 root 1 20 0 13M 2536K kqread 0 0:37 0.03% rtsold92454 root 1 20 0 13M 2596K select 0 0:26 0.02% rtsold92282 root 1 26 0 13M 2492K select 3 0:00 0.00% rtsold92284 root 1 52 0 13M 2488K select 3 0:00 0.00% rtsold92311 root 1 23 0 13M 2480K select 2 0:00 0.00% rtsold99757 root 1 30 0 13M 2580K nanslp 2 0:02 0.00% cron13623 root 1 52 0 12M 2500K select 0 0:00 0.00% dhcp6c 6935 root 1 52 0 12M 2312K ttyin 2 0:00 0.00% getty31883 root 1 52 0 12M 2264K piperd 0 0:00 0.00% daemon63237 root 1 52 0 12M 2264K piperd 1 0:00 0.00% daemon69359 root 1 20 0 12M 2260K piperd 2 0:00 0.00% daemon25740 root 1 20 0 12M 2260K piperd 3 0:00 0.00% daemon97600 root 1 20 0 12M 2256K piperd 3 0:01 0.00% daemon66976 _flowd 1 20 0 12M 2668K select 1 0:47 0.00% flowd66951 root 1 20 0 12M 2420K sbwait 3 0:00 0.00% flowd38535 root 1 20 0 12M 2276K select 2 0:26 0.03% powerd20831 root 1 20 0 12M 2444K select 3 0:13 0.00% radvd66622 root 1 20 0 12M 2284K sbwait 1 0:33 0.05% route63345 nobody 1 20 0 12M 2172K sbwait 3 0:17 0.00% samplicate95617 root 1 20 0 12M 2140K nanslp 0 0:00 0.00% sleep 958 root 1 24 0 12M 2140K nanslp 2 0:00 0.00% sleep
Some things get rather upset when you block DNS queries and therefore ramp up the amount of queries. That could be what's happening.It also could be something else in your firewall config and it temporarily went away because you restarted the firewall.
Some things get rather upset when you block DNS queries and therefore ramp up the amount of queries. That could be what's happening.
Quote from: CJ on August 24, 2023, 01:21:58 pmSome things get rather upset when you block DNS queries and therefore ramp up the amount of queries. That could be what's happening.yep. Home Assistant sending 1-2Mbps (!) of DNS over TLS attempts to Cloudflare. Changing the fw rules from "reject" to "block" caused HA to stop basically DoS'ing opnsense.