FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jera
Staff
Staff
Article Id 423905
Description This article explains how to get back into the FortiGate GUI after multiple HTTPS processes caused a high CPU utilization.
Scope FortiGate.
Solution

 

image.png

 

  • Look at the output to see that the CPU is being maxed out by several httpsd.
  • Use the command 'diagnose alertconsole list' to confirm the reason behind the httpsd spawn process.

 

image.png

 

  • Observe that there are several login attempts from various public IPs in the output.
  • To address the issue and restore access to the FortiGate, ensure that the HTTP and HTTPS services are disabled for administrator access on any external or internet-facing interfaces (such as wan1 or wan2). See System Administrator best practices.
  • While on console, execute the following command to disable HTTP and HTTPS to the internet-facing interfaces:

 

config system interface

    edit <interface_name>      <----- Internet-facing interface.

        unselect allowaccess https http

    next 

end

 

  • Lastly, use the command below to restart the process.

 

fnsysctl killall httpsd

 

 

Related article: 

Technical Tip: Regularly audit and restrict open ports on FortiGate public interfaces