Created on
01-10-2024
06:06 AM
Edited on
11-10-2025
06:21 AM
By
Jean-Philippe_P
| Description | This article describes how to troubleshoot high CPU usage caused by the IPS process. |
| Scope | All FortiOS. |
| Solution |
On systems where a high CPU load is suspected to be caused by IPS-based scanning, the IPS engines can be set to 'bypass' mode. The following command can be used for testing to confirm if the CPU load is caused by IPS.
Note that this will bypass all IPS scanning. The commands are intended for testing or in urgent cases of high CPU load as a temporary workaround.
Use the command below to bypass the IPS engine.
diagnose test application ipsmonitor 5
In this mode, the IPS is running, but it is not inspecting traffic.
After proceeding to disable the bypass with the same command:
diagnose test application ipsmonitor 5
As an alternative to bypassing traffic inspection, it is also possible to temporarily stop and restart all IPS engines. Use the following commands:
diagnose test application ipsmonitor 98 <-- Stops all IPS engines.
diagnose test application ipsmonitor 97 <-- Starts all IPS engines again.
Stopping the IPS engines will immediately halt all IPS inspection and related background processes.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.