Skip to main content
joel_b
New Member
January 13, 2014
Question

Policies take long to load

  • January 13, 2014
  • 7 replies
  • 10780 views
Hi we have over 2000 policies on our Fortigate 3600 running 5.0.5. It takes a couple of minutes for the policies to load in the GUI. Does anyone know of a tweak that can speed this up a bit please? Is anyone else having this issue? Thank you.

    7 replies

    emnoc
    New Member
    January 14, 2014
    What version of broswer?
    joel_b
    joel_bAuthor
    New Member
    January 14, 2014
    I' ve tried IE 11, Chrome v32 and Firefox v26 but the policies still take a couple of minutes to load.
    emnoc
    New Member
    January 14, 2014
    HTTP or HTTPS ( I' m assuming HTTPS ) ? fwiw: I just loaded 1430 policies in a 3600C running 5.0.3, firefoix 26.0 on MACOSX. Not blazing fast, but it took just under 35secs from kicking the firewall policies tab. CPU runs at a constant 65% on this device, wth no UTM, maybe 12 active vpns. suggestions; try looking at diag sys top and check how many running process. try reducing unneeded services check access from 2 or 3 client machine to ensure it' s not your browser or host that' s screwing up open a ticket with fortinet support fwiw: unlesss you have a need to run 5.0.5 , I would not run it due to it' s being quite newer. My immediate thoughts for the slowness might be in the http daemon. So you can try to kill it and let it restart diag sys kill -9 <proc id>
    joel_b
    joel_bAuthor
    New Member
    January 14, 2014
    Thank you sir. I' ll try your suggestions and let you know how it goes.
    joel_b
    joel_bAuthor
    New Member
    January 14, 2014
    Oh and yes it is https access. When we were running 5.0.4 we ran into high CPU and memory utilization issues but we had UTM features enabled. Fortinet support said it was Bug ID 0220191 - high CPU usage on urlfilter deamon after the cache is full. The fix was to update to 5.0.5. THe update to 5.0.5 fixed the high cpu and memory utilization (CPU averages less than 10% now) but the problem with the policies taking long to load persisted. Everyone on the security team is having the same issue with the policies. We tried the Fortimanager and the policies loaded much faster on that ... but the trial period ended on that and we did not get to keep it ...
    joel_b
    joel_bAuthor
    New Member
    January 14, 2014
    Fortinet support said that this is a bug (ID 0213699) that will be fixed in 5.0.6 ...
    Jordan_Thompson_FTNT
    Staff
    Staff
    January 14, 2014
    Fortinet support said that this is a bug (ID 0213699) that will be fixed in 5.0.6 ...
    Correct. Note that performance will be slightly slower on Chrome + HTTPS when using the default unsigned server certificates as Chrome ignores caching in this setup.