Skip to main content
Contributor III
September 14, 2004
Question

CPU maxes out & all traffic stops passing

  • September 14, 2004
  • 24 replies
  • 12079 views
We are using an 800 running 2.8 MR4. On Friday, we were on 2.5 MR8, were having same cpu maxed out problems, so we were told to upgrade. The problem still exists, wondering if anyone else is experiencing same issues. We are a wireless ISP with somewhere around 900+ customers coming through the core. The 800 sits at the core, and all traffic goes through it. When all traffic stops, bossman gets upset, so I need a fix soon!! I have been noticing that it' s been detecting code red viruses, not seeing it in the logs, but in the recent virus detections on system status page. Wondering if it' s really dropping those entries, or if it' s passing it to adjacent routers?? Is anyone else experiencing cpu maxing out?

    24 replies

    Contributor III
    September 14, 2004
    High CPU has been a constant problem for us. I had a 800 before with a 25 Mb DS3 link and it constantly ran at above 80% and eventually 98%-100% and all WEB traffic would stop. I just upgraded to a fortigate 1000 runng 2.50 MR10. It is still running at aroud 90% and we had some traffic stopped occassionally when the CPU shoots up. I turn off all disk logging and it seems to run a little better but CPU usage still shoot up to 75%-80%. I have a few fortigate 100s, the one without a hard drive. They seem to be okay and never gave me a problem. But then again those unit typically only connect to a T-1 or DSL with much less traffic. I am afraid to upgrade my 1000 to 2.80 MR4. Their web site claims that the fortigate 1000 will support Gb link. I reaaly do not see how that is possible, maybe you have to turn off all anitivirus and IDS/IPS scanning. Then what is the point?! Please let me know how you make out with your issue. I am interested to know. Thanks
    Contributor III
    September 14, 2004
    Yes, if we turn off all virus scanning, it does bring the cpu down to where it should be, however, the only thing we' re using this for is for the virus protection & IDS. So if we can' t use those function, the box is really no good to us.
    Contributor III
    September 14, 2004
    We have experienced similar things lately. We have 2 FG400s in an Active-Active HA group running v2.50 MR9. I also monitor these firewalls via 2 SNMP checks for high session count (possible virus in the network) and system uptime (to see if it recently rebooted). Both of these checks started going crazy yesterday. However, when I checked the firewalls, they seemed fine. When these alerts happened, the connection to any Internet site was extremely sluggish and accessing our websites from outside was as well. Furthermore, accessing the web-based GUI was not happening. After several alerts sent to me, I checked the firewall again and my secondary firewall showed up with a red circle and X in the cluster members section of the GUI. Monitoring only showed the local firewall. We suspected just about everything but the units themselves - our network switches, the switch going to the Internet router, the cable for HA - but it turns out there seems to be an issue with the latest antivirus update that was pushed to us. After spending a while on the phone with support last night, this was the conclusion that we reached. I was told to either go to MR 10 or I could disable the AV scanning on the rules using HTTP. Apparently, Fortinet R&D is researching this " known issue" and hope to have something to fix this soon if not today. In the meantime, we have disabled AV scanning on the HTTP traffic to our published websites. Not a great solution since we bought the Fortinets for their AV capability.
    gregs
    New Member
    September 14, 2004
    Let me add my 2 cents. I have a FG3600 OS 2.8, + hard disk. CPU usage is constant 70% with spikes to 93% only 2500 sessions 28% memory used. I only have a 6Mb internet connect at this point, it is supposed to handle Gb. We will be going to a 100Mb connect in the near future. I am very concerned now that this box will not handle the traffic. My reseller tells me 70% is ok but any higher is a problem. I have tuned off ALL logging today to see if it makes a difference, it does not. Perhaps I need to open a support incident to resolve the problem. Greg
    Contributor III
    September 16, 2004
    gregs, with a 3600 running at CPU usage of 70% on only a 6Mbit connection, I would definitely call Fortinet and get a case open. I would think this would be a cause for concern. The big selling point of these boxes from a technical perspective is the ASIC. This is supposed to offload AV, IDS, Policy Checking and IPSec from the CPU to give better performance. The 3600 should be able to handle 6Mbit with it' s hands tied behind it' s back (figuratively speaking).
    Contributor III
    September 15, 2004
    I have similar problem last 2 days. I just get connection loss and can not use fw GUI or ssh. I need some suggestion.My device is 800 now with 2.50 MR9 , url block on and disable IDS feature now.
    Contributor III
    September 15, 2004
    We' ve experienced a similar problem as discussed HERE We don' t use AV for HTTP traffic however. The problem we had was a result of POP traffic. It appears that going to MR10 resolved our issues (no more problems late yesterday or so far today)
    UkWizard
    New Member
    September 16, 2004
    take there specs with a pince of salt (as all manufacturers).
    gregs
    New Member
    September 16, 2004
    Thanks all for the replies. I did not get the firmware version right (brain fade) I have 2.5 build 269 which is MR9. I have been in touch with my reseller who tells me to upgrade to MR10. I am going to do that tomorrow AM. It' s a PITA now ' cos the box is in production. I am going read the instructions to prepare for the upgrade, any known caveats that I should watch for? Trombone, yes that is what I assumed. I have a po issued for 2 FG1000' s, I have put that on hold ' till this is resolved. 6Mb is nothing, we bought the 3600 and paid the big dollar because eventually we may get a 100Mb connect. Philink, as above got the ver wrong. Who woulda thunk that marketing would be exaggerated. It would be nice to know exactly what it will handle. Wiz, pinch me where? Greg
    Contributor III
    September 16, 2004
    One thing I found was that Fortigate might be able to handle the 100 Mb with a few sessions but not 10 Mb with many sessions. I noticed that when I had many sessions flowing thru Fortigate (4000+), it wolud peak my Fortigate to 98%. I guess when Fortinet spec out their units, they simply have one or two PC pushing a few session with lots of traffic thru Fortigate, instead of simulating with many PCs and many sessions just like in the real world. Just my 2 cents.
    gregs
    New Member
    September 17, 2004
    FYI: 2.50 299 MR10 fixes the CPU high utilization on my 3600. We did the upgrade to 2.50 299 this morning. There were absolutely no hitches. It did not lose any of the config data and it came back up in transparent mode. Mind you I was prepared, I had my laptop connected thru the console port and also thru Port 1. I also had a copy of the config ready to reload. I will also post this as a new topic. Greg
    Contributor III
    September 22, 2004
    Pasdargent, I would be very weary of using SNMP with v2.5. We have a ticket with Fortinet with our FGT500 with respect to SNMP v2c. Since I don' t have any insight into the FortiGate development this is only what it appears to me what happens when things go bad. First off it apears that the SNMP daemon uses up too much memory and start choking other process. The only way you can see this is by connecting a serial cable to the FGT500. If you do that you' ll see errors spewing out with stuff like processes being killed restarted and killed over and over. The box then starts dropping sessions... more packets get dropped and the only way to recover is to reboot the FGT500. As a work around we now restart the SNMP daemon on FGT500 after every poll. However this only works if the box is not overloaded by say an attack (by using NESSUS http://www.nessus.org/ as an example). Once you attack the box with a few concurrent attacks (like any script kitty would do ) it again keels over in the same way after about 20 minutes. I could understand it if the problem was that it dropped a few sessions when the box was overloaded. That would be expected. What is not expected is that when the load is removed the box does not recover from the crash. Fortinet refuses to fix this problem in v2.5 and keep telling us to move to v2.8. Based on my readings of the forums I don' t think v2.8 is ready for production. Fortnet also says no one else is using SNMP or they would have reported our problem as well so we must be a unique site. I can understand that as a manufacturer I wouldn' t want to spend my precious time dealing with an old release when I need to get a new release functional. My request to you is to if you' re experiencing any of these problems to please contact Fortinet with your issues and maybe if enough of us get together we could get a fix for this issue. Kind regards, SpyderGeer FGT500 v2.5 MR10 Build 299 and interim release Build 315
    UkWizard
    New Member
    September 22, 2004
    2.8 MR3 had worse memory leaks than all the other versions, MR4 seems better judging by the feedback form the forum users. Try the 2.5 MR10 and see what happens, then 2.8 MR4 after that if it still occurs. if it still occurs after that, i would highly recommend factory resetting the unit and restoring the config (or do it again from scratch, if poss). I have seen in the past where a box does really strange stuff, including freezing up. Caused by a firmware upgrade, seemed to screw the config somehow. Only a factory reset would fix it. Thats a last resort option though.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!