Issue:
When an WithSecure endpoint product is installed on a computer or server, there is high CPU usage and applications are experiencing performance issues. The connectivity of some applications can also be slow or blocked completely.
Issue affects all WithSecure clients:
- Elements Endpoint Protection EPP for Computers
- Elements Endpoint Protection EPP for Servers
- Business Suite Client Security
- Business Suite Server Security
- Business Suite Email and Server Security
Resolution:
Performance issues can for example be the result of:
- Connectivity issues to the Security Cloud
- Misconfigured Application Control
- Server Share protection
Connectivity issues to the Security Cloud
What is Security Cloud?
When Security Cloud is enabled on WithSecure endpoint products, it connects to WithSecure Backend to check reputation and other objects. WithSecure endpoint products have database updates which can detect the malware without connection to cloud, but, to check the reputation we need cloud connection. There is the local cache, but it comes first from the cloud, where the whitelisting of false positives is done.
When you enable Security Cloud, you also need to whitelist the following domains on your Firewall, as the endpoints need to communicate to Security Cloud.
- *.withsecure.com
- *.fsapi.com
Note: The domains mentioned above needs to be whitelisted to your firewall or proxy. In case you have enabled some proxy in your environment, the client reads it via discovery service and tries to connect to *.fsapi.com through it.
If you have allowed the connectivity in your firewall, you can test the connection in two ways:
1. Opening the URLs on Browser and they should respond with ok:
2. Use WithSecure Connectivity Tool, which is available in the installation folders of Elements Endpoint Protection (EPP for Computers and EPP for Servers), Business Client Security and Business Suite Server Security. With the tool you can view the list of addresses the product connects to and check the connectivity towards them.
Note: For Client Security the tool is available in 15.20 and later versions, and for Server Security 15.10 and later.
The tool is located in the following folder:
- Client Security: C:\Program Files (x86)\F-Secure\Client Security\ui\fsconnectionchecker.exe
- Server Security: C:\Program Files (x86)\F-Secure\Server Security\ui\fsconnectionchecker.exe
- Elements EPP for Computers/Elements EPP for Servers: C:\Program Files (x86)\F-Secure\PSB\ui\wsconnectionchecker.exe
For older Client Security and Server Security releases, you can download the tool from here: https://download.withsecure.com/connectivitytool/ConnectionChecker.exe
Misconfigured Application Control
If you have a premium subscription of Business Suite or Elements Endpoint Protection, it will include the Application Control feature.
If the product is using high amounts of CPU performance, make sure you have not set the Application Control Global rule as Allow and monitor all applications. This setting should be used only during testing to find out which applications need exclusion rules, since it will affect the performance of devices.
Also make sure that you have not created Application control exclusion rules which only include a SHA1/SHA256 as a condition, since the calculation of the SHA1/SHA256 will require some CPU performance. Instead, we recommend using other conditions (such as the target path, etc.) in conjunction with the file hash condition.
Server Share Protection
Elements Endpoint Protection for Servers has a Server Share Protection feature, which can cause slowness or high CPU usage in certain situations. If you have enabled it on your Elements EPP for Servers installation, try disabling Allow and report mode for it:
- Log in to the Elements Endpoint Protection portal
- Go to the Profiles page
- Go to the For Windows Servers tab
- Select the profile you want to edit
- Go to the Server Share Protection settings page
- Disable Allow and report mode
- Click Save and publish
Restart the server after disabling the feature and see if the CPU usage has decreased. If not, try disabling Server Share Protection feature off completely.
Article no: 000030468