A network security engineer is investigating why a firewall's dataplane CPU is consistently at 95%. After reviewing the session table, they notice a large number of sessions in a 'discard' state. Which action should the engineer take first to resolve the high CPU utilization?
Sessions in a discard state often result from a security policy rule with an action of 'deny' and no notification to the client, such as a 'drop' action. When the firewall silently drops packets, sessions may linger until they time out, consuming resources. Reviewing the security policy to identify such rules and adjusting them to send a reset or ICMP unreachable can clear sessions faster and reduce CPU load.
Why this answer
Sessions in a discard state are often caused by a security policy rule that silently drops traffic without sending a response. This can lead to a large number of sessions lingering in the session table, consuming dataplane CPU. Reviewing and adjusting the security policy to send resets or ICMP unreachable messages can help clear these sessions more quickly and reduce CPU utilization.
Exam trap
The trap here is assuming that session timeouts or hardware offload are the primary causes of high CPU due to discard sessions.