High current session, leads to high CPU and causes internet downtime
- September 29, 2017
- 1 reply
- 58710 views
Good day!
I'm in charge of networking for a company, this company have roughly 150 employees in office.

However, recently we encounter an issue, there seems an high CPU usage and this causes the outgoing/incoming internet traffic to crawl and all employee unable to connect to the internet. When it occurs, the Current Session (GUI) reported up to 5,000 sessions! To further investigate this matter, I spend weeks observing the traffic in Current Session (GUI), in normal usage, fortigate 60D able to handle 1,000 session to 2,700 session without hiccups.
We even tried use CLI to observe the stats and it reports ipsmonitor and scanunitd uses the most resources during high load.
Another note is that during high cpu load, while internet traffic is essentially disabled. LAN still work, employees are able to access NAS through the network, (DHCP is handled by the same Fortigate 60D). This mean that the fortigate is still working intranet, but somehow 'stuck' in internet.
According to this spec provided by Fortigate, 60D suppose able to handle Concurrent Session (TCP) up to 500,000! but why it can't even handle 5,000 Current Session??
Did we setting up the policy wrongly? How can I handle the traffic in a better way to have high availability? or should we upgrade to a better fortigate firewall like 100 series?
P/s: I can't upload more than 1 file. Where can I attach more file for better conveying the message?