Description | This article describes the use of the IPS process in FortiGate. |
Scope | FortiGate. |
Solution |
In FortiGate, IPS (Intrusion Prevention System) are used to detect or block attacks/exploits/known vulnerabilities with signature-based defense.
There are three main processes within the IPS:
diag test app ipsmonitor 1 <- Will display basic information on ipsmonitor.
Note that ipshelper is always at index 0 in the IPS process.
The number of the engine depends on different models/hardware.
Index 1 will be the master IPS engine which is responsible for:
They most likely will have higher CPU/Memory usage than the other IPS engine workers.
For the last point, it is possible to see the process having a significantly higher CPU usage (i.e. in the output of command diagnose sys top). Investigate further with the following commands:
After, dump details about the process IDs:
diagnose sys process pstack <PID> <- Dump process userspace stack.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.