IPS Engine CPU load - ssl deep inspection
Hi,
I wonder if none of you is having issues with the IPS-Engine (flow mode) on Forti-OS 6.2.x (6.2.3) and CPU-load? We have a huge problem (on a FGT 60F and a FGT 100D), after installing Forti-OS 6.2.x:
When activating SSL-Deep-Inspection for our outgoing policies, the first thing is that some sites (HTTPS) do not open on the first attempt, but when reloading the site. (On the first attempt there is a ssl error page, the second attempt then works). (We have imported the SSL certificate from the FGT to the clients browsers).
The second BIG issue is, that 3 cores are sometimes freaking out (99.9% CPU load caused by ips engine). If this happens, nothing works. (Internet is dead). After a few seconds /minutes, the ips engine goes back to normal load.
I am in contact with FGT support and we try to hunt down the problem, which is definitly caused by IPS-Engine & flow-mode & ssl-deep-inspection. After analyzing the logs (the ips engine seems to crash - after not reacting for 30sec - and got restarted) During these 30 seconds nothing (I mean the Internet) is working. We are still examining debug-logs with FGT support.
When the 99% CPU is happening, there is no high amount of open sessions (900-1500) and no massive throughput. (Last time we got a throughput of 2Mbit (all policies summed up).
The only workaround for us is only activationg ssl-certificate-inspection, which is a massive security problem, because SSL-connections will not be scanned for e.g. viruses.
Hope to get it sorted.
