FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
abarushka
Staff
Staff
Article Id 228275
Description This article explains details about the output of get system performance status.
Scope All FortiOS versions.
Solution

This article will use the following example output from the get system performance status command:

 

get system performance status
CPU states: 1% user 0% system 0% nice 99% idle 0% iowait 0% irq 0% softirq
CPU0 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq
CPU1 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq
CPU2 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq
CPU3 states: 5% user 0% system 0% nice 95% idle 0% iowait 0% irq 0% softirq
Memory: 3112532k total, 1018512k used (32.7%), 1863964k free (59.9%), 230056k freeable (7.4%)
Average network usage: 99 / 9 kbps in 1 minute, 99 / 4 kbps in 10 minutes, 102 / 21 kbps in 30 minutes
Maximal network usage: 144 / 37 kbps in 1 minute, 158 / 61 kbps in 10 minutes, 1069 / 4463 kbps in 30 minutes
Average sessions: 20 sessions in 1 minute, 19 sessions in 10 minutes, 18 sessions in 30 minutes
Maximal sessions: 32 sessions in 1 minute, 35 sessions in 10 minutes, 56 sessions in 30 minutes
Average session setup rate: 0 sessions per second in last 1 minute, 0 sessions per second in last 10 minutes, 0 sessions per second in last 30 minutes
Maximal session setup rate: 3 sessions per second in last 1 minute, 12 sessions per second in last 10 minutes, 21 sessions per second in last 30 minutes
Average NPU sessions: 0 sessions in last 1 minute, 0 sessions in last 10 minutes, 0 sessions in last 30 minutes
Maximal NPU sessions: 0 sessions in last 1 minute, 0 sessions in last 10 minutes, 0 sessions in last 30 minutes
Average nTurbo sessions: 0 sessions in last 1 minute, 0 sessions in last 10 minutes, 0 sessions in last 30 minutes
Maximal nTurbo sessions: 0 sessions in last 1 minute, 0 sessions in last 10 minutes, 0 sessions in last 30 minutes
Virus caught: 0 total in 1 minute
IPS attacks blocked: 0 total in 1 minute
Uptime: 1 days, 23 hours, 46 minutes

 

The 'CPU states' section refers to average load on the CPU for the whole unit, whereas 'CPUx states' refers to each core on the CPU:

 

CPU states: 1% user 0% system 0% nice 99% idle 0% iowait 0% irq 0% softirq

The 'user' field refers to CPU usage in userspace (e.g. running daemons). The processes using this portion of the CPU can be tracked via 'diag sys top' or similar commands.

The 'system' field refers to CPU usage in kernel space. Generally, the commands in this article are used to track what is using this portion of the CPU: Troubleshooting Tip: FortiGate CPU Profiling - Fortinet Community.

Here, 'softirq' refers to the CPU processing hardware interrupts. This is usually network traffic which is not offloaded to the NPU, and must be processed by the CPU instead. The difference between 'Average sessions' and 'Average NPU sessions' may show if a majority of the sessions are offloaded.

The values 'nice', 'iowait', and 'irq' should generally never be seen as high. If these values are causing high CPU usage, contact TAC.

In the Linux context, the 'nice' value refers to a priority given to a process. Processes with a high nice value behave nicely when pre-empted. While it is not possible to output this nice value in a FortiOS context, in most cases no impact will be observed when the 'nice' category is high.

 

'Freeable' memory in the following section refers to the amount of cached memory that can be freed. It is not included in either freed or used memory.

 

Memory: 3112532k total, 1018512k used (32.7%), 1863964k free (59.9%), 230056k freeable (7.4%)

 

The first value under 'Average network usage' refers to inbound traffic, while the second value refers to outbound traffic:

 

Average network usage: 99 / 9 kbps in 1 minute, 99 / 4 kbps in 10 minutes, 102 / 21 kbps in 30 minutes

 

Similarly, the first value under 'Maximal network usage' refers to inbound traffic while the second value refers to outbound traffic:

 

Maximal network usage: 144 / 37 kbps in 1 minute, 158 / 61 kbps in 10 minutes, 1069 / 4463 kbps in 30 minutes

 

The maximal network usage, maximal sessions, maximal session setup rate, maximal NPU sessions, and maximal nTurbo sessions fields were added in FortiOS 7.0.4 GA and 7.2.0 GA or higher.

 

See Checking CPU and memory resources in the product documentation for more information about FortiGate system performance statistics.