Nour
Staff
Created on
08-13-2024
01:40 AM
Edited on
12-17-2024
07:12 AM
By
Jean-Philippe_P
Article Id
332574
Description | This article describes the behavior seen when FortiGate IPSEngine enters fail open mode due to GRE traffic, causing high CPU and an increased load on the FortiGate. |
Scope | FortiGate with pass-through GRE traffic that is IPS inspected/UTM enabled. |
Solution |
Behavior and symptoms (v7.0/v7.2/v7.4v/7.6):
diagnose sys session filter clear <----- Clear previous filters.
Note: It is possible to correlate the high CPU/IPSEngine fail-open with specific timestamps where an increase in GRE traffic bandwidth is seen. |