Description | This article describes a solution for the issue of the IPS Engine remaining in a D state during high DNS traffic loads on the firewall. |
Scope | FortiGate v7.2.7, v7.0.15. |
Solution |
When the DNS filter is configured with an external-ip-blocklist and during high DNS traffic load, the IPS Engine remains in D status and the DNS resolution fails: diagnose sys top 2 50 The highlighted line below shows that the IPS Engine is querying FOS for the External IP Blocklist and ultimately entering the D state:
# fnsysctl cat /proc/38256/stack <----- 38256 is the process ID of ipsengine from the above output. This issue has been resolved in v7.0.16, v7.2.9, v7.4.4, v7.6.0 Workaround: Remove the external-ip-blocklist from the DNS filter. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.