Skip to main content
Miata
New Member
July 30, 2015
Solved

High CPU and Memory Usage

  • July 30, 2015
  • 31 replies
  • 242475 views

Hi guys

 

So my FG-60D running 5.2.3 has been at 100% CPU and about 90% memory recently so I thought I would run the diag sys top command as shown below. 

 

From this command I can see that the scanunitd and IPS engine it taking most of my CPU usage. I don't have vulnerability scanner but I have AV enabled on 17 different policies. I think the box is being overworked, but can I restart any processes or do you guys have any other advice?

 

Run Time: 42 days, 19 hours and 54 minutes 62U, 0N, 37S, 1I; 439T, 40F, 189KF scanunitd 7079 R < 68.4 3.7 ipsengine 602 S < 19.2 13.1 httpsd 7717 S 2.3 4.2 httpsd 7718 S 1.9 4.2 httpsd 7737 S 1.7 4.2

 

I also ran get sys performance - Output below

 

CPU states: 75% user 25% system 0% nice 0% idle CPU0 states: 75% user 25% system 0% nice 0% idle Memory states: 93% used Average network usage: 6282 kbps in 1 minute, 2754 kbps in 10 minutes, 2200 kbps in 30 minutes Average sessions: 1995 sessions in 1 minute, 2178 sessions in 10 minutes, 1824 sessions in 30 minutes

 

If you have any form of advice in terms of how to manage this more successfully or anything to restart/kill then please let me know, would be greatly appreciated.

 

Kind regards

Miata

Best answer by frajico

Finally, we realized that some interfaces of Fortigate unit that were configured as trunk interfaces (multiple vlans), were receiving more traffic than they have to (have to receive only 1 vlan traffic, and was receiving 10 vlan traffic), so interface got oversubscribed and CPU of Fortigate raised almos al 100%. Allowing only the 1 vlan on the switch, solved the issue.

Check for overloaded / oversubscribed interfaces traffic.

31 replies

gschmitt
New Member
July 30, 2015

Miata wrote:

 

scanunitd 7079 R < 68.4 3.7

diag sys kill 11 7079

 

It shouldn't get that high

Miata
MiataAuthor
New Member
July 30, 2015

Hi

Thanks for the comment.

 

My mistake, this is just an example of the diag sys top command, there are many others that show it fluctuates between the given value and 90%+.

 

Miata

ecsupport
New Member
July 31, 2015

I've noticed the same issue on 60D, 90D and others since upgrading from 5.0.10 to 5.2.3

 

CPU spikes from IPSengine primarily and scanunitd put average cpu about double what it was before upgrading.

 

I can kill/restart ipsengine but problem comes back. I disabled SSL cert inspection in case that was doing it but no go. Still occurs even on boxes that dont use ANY IPS policies (although app control is enabled on surfing).

 

Bug in 5.2.3??

Miata
MiataAuthor
New Member
August 10, 2015

Well I think that generally I'm over working the box, as it is only a 60D. These boxes can't really take a lot of tasks, especially if one of them is to scan every bit of traffic that comes in and out of the box, as well as a bunch of other tasks which I couldn't mention within the size of this text box!

 

I noticed the vulnerability task was enabled, and so assumed this would be scanning loads of traffic both incoming and outgoing, so I set this only to late at night to run security checks etc. I also killed/restarted the IPS engine which has also helped bring down the processing usage.

Miata

vjoshi_FTNT
Staff
Staff
August 10, 2015

Hi,

 

Yes, you can see high CPU/Memory if you have many task beyond the device capability, the box will exhaust.

 

However, best thing to do is to optimize the settings.

 

Like, reducing the session-ttl ( which is 3600 seconds may not be needed in most of the networks) and when can have increased session-ttl for specific protocols and ports if needed.

 

Also, tweaking the below values (these are not default, they are recommended values):

 

config system global set tcp-halfclose-timer 30 set tcp-halfopen-timer 30 set tcp-timewait-timer 0 set udp-idle-timer 60 end

 

Above techniques will help to optimize the performance of a device.

 

 

vjoshi_FTNT
Staff
Staff
August 10, 2015

Just to add, Even for the IPS profiles, instead of using the default sensor list, fine tune it by having specific signatures like, with Server based / OS based and so on.

 

Also, instead of killing a process, I would recommend restarting the application as shown below:

 

 # diagnose test application ipsmonitor IPS Engine Test Usage:    97: Start all IPS engines    98: Stop all IPS engines    99: Restart all IPS engines and monitor

 

 

mscheiber
New Member
November 17, 2015

We see the same symptons on our FGT60D since we  upgraded from 5.0.9 to 5.2.4 now CPU spike at 100% and of course response times are very very slow.

 

There was no change in the amount of sessions nor of the traffic which is going through the FGT60D and with 5.0.9 there was no problem cpu was idled most of the time. So 5.2.4 is doing something different causes high cpu usage.

 

Is it a bug? Or did someone find out what causes the the high cpu usage for the ipsengine/monitor since the upgrade to 5.2.4

 

zeki893
New Member
December 11, 2015

having same problem with 5.2.3 scanunitd is 100% and it won't kill the process when i try diag sys kill 11

 

Anybody know what to do if diag sys kill 11 doesn't work?

SCSIraidGURU
New Member
December 7, 2016

I have worked with Cisco, Fortinet, Checkpoint and other firewalls over 35 years.  17 policies on a 60D?   Seems like overkill.   Can you consolidate the policies and processes down?     I would not try that on my 800C in my data center.   I limited policies to default that covers 85% of users.  A custom policy for 10% of the users.  A third policy for 5% of users.   With most firewalls.  You want to create policies to cover most of your users.    Can you give more details on why you have so many policies on a 60D? 

TIBarigui
New Member
March 16, 2017

Hello!

 

We have a 240D Fortigate and we've been through CPU problems as well.

 

We had memory problems before it. Turning into proxy mode gave us some breath, but we had to turn back to proxy because of safe search. Now, since the last upgrade to 5.2.10, our CPU is running around 80% average. We have tops of 100% sometimes.

 

I already looked at interfaces througput as the other guy said, but everything is fine. The problem is processes getting high CPU.

 

 

CPU [|||||||||||||||||||||||||||||||||||| ] 90.4% Mem [|||||||||||||||||| ] 47.0% 1866M/3955M Processes: 20 (running=5 sleeping=88)

PID RSS ^CPU% MEM% FDS TIME+ NAME * 80 478M 67.0 12.1 26897 39:30.85 proxyd [x3] 27819 221M 54.1 5.6 76 07:00.85 ipsmonitor [x4] 81 39M 41.1 1.0 35 28:02.44 scanunitd [x3] 6289 29M 7.3 0.7 15 00:01.49 sshd [x4] 61 30M 5.6 0.8 26 59:16.53 miglogd 92 108M 3.7 2.8 20 01:37.52 urlfilter 122 52M 0.9 1.3 14 26:58.57 updated 27423 80M 0.0 2.0 14 00:02.89 pyfcgid [x6] 35 3M 0.0 0.1 5 00:00.32 mrvl3135_worker 6214 14M 0.0 0.4 22 00:01.29 cw_acd 43 28M 0.0 0.7 13 01:21.60 cmdbsvr 48 12M 0.0 0.3 90 01:49.82 zebos_launcher [x12] 2874 14M 0.0 0.4 35 00:14.78 iked 60 12M 0.0 0.3 12 00:02.12 uploadd 62 11M 0.0 0.3 8 00:00.97 kmiglogd 63 36M 0.0 0.9 52 00:10.30 httpsd [x4] 65 11M 0.0 0.3 8 00:00.00 getty 69 11M 0.0 0.3 11 00:07.73 merged_daemons 70 13M 0.0 0.3 12 00:00.33 fnbamd 71 11M 0.0 0.3 11 00:00.10 fclicense

BNDP
New Member
December 20, 2017

Hi Guys,

   Requires solution for high cpu utilization in FW-300C firewall, you can find the system top performances when it reached the high spikes,

Run Time: 34 days, 9 hours and 38 minutes 57U, 0N, 42S, 1I; 2016T, 819F, 144KF ipsengine 28896 R < 94.6 3.2 updated 88 S 2.9 1.0 miglogd 89 S 1.7 1.3 wad 91 S 0.5 0.9 sqldb 80 S 0.0 3.5 iked 87 R 0.0 2.8 httpsd 25638 S 0.0 2.1 httpsd 25477 S 0.0 2.1 miglogd 63 R 0.0 1.6 reportd 81 S 0.0 1.6 cmdbsvr 44 S 0.0 1.6 pyfcgid 28835 S 0.0 1.6 scanunitd 28412 S < 0.0 1.3 scanunitd 28413 S < 0.0 1.3 scanunitd 86 S < 0.0 1.3 pyfcgid 28824 S 0.0 1.3 pyfcgid 28842 S 0.0 1.2 proxyworker 85 S 0.0 1.1 pyfcgid 28765 S 0.0 1.1 dnsproxy 107 S 0.0 1.0

 

Please help on this.....

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!