Description | This article discusses IPS entering fail open mode. |
Scope | FortiGate. |
Solution |
When observation on the FortiGate with IPS entering fails open mode frequently:
... msg="IPS session scan resumed, exit fail open mode." msg="IPS session scan resumed, exit fail open mode." This might lead to a few suspects:
Check if there is any high Memory/CPU on the FortiGate:
diagnose sys top get sys performance status
Use the below command to check if there is a constantly crashed:
diag debug crashlog read
Check the IPS buffer setting on the FortiGate by:
diag test app ipsmonitor 1
Try to increase the IPS buffer by:
config ips global set socket-size <x> end
If the issue still persists, kindly collect the info above and contact Fortinet support.
Related Document: |