Created on 11-07-2021 10:26 PM Edited on 02-28-2024 09:47 PM
Description
This article describes how to optimize the system when high CPU and/or memory issue is happening with IPS process.
Scope
FortiGate.
Solution
# config ips globalset socket-size [integer, 0-512] <----- IPS socket buffer size. Max and default value depend on available memory. Lower value reduces memory usage.set engine-count [integer, 0-255] <----- Number of IPS engines running. The default value of 0, FortiOS sets the number to optimize performance depending on the number of CPU cores. Reduce it to the number of cores the FortiGate box has.set database [regular|extended] <----- Regular protects against the latest common and in-the-wild attacks. Extended includes protection from legacy attacks.end
After changing the engine, database and socket size, restart the IPSEngine using the following command:
diag test app ipsmonitor 99
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.