I just bought a 60D for my home internet (250mbps). However when I have Application control, antivirus or web filtering enabled it maxes out the CPU to 100% and throttles the speed to 40mbps. I have logging completely off and I'm running 5.4 however it does the same with 5.2.5.
As soon as I disable the UTM features it comes back. I did a diag sys top and it shows the IPS service as using almost all of the CPU. Any ideas?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello J Cortes, The IPS is a powerful tool to be configured. One of the biggest fault is to apply for all traffic, not specifying the application (http, https, ftp, smtp, etc). Follow some commands to debug IPS sensor.
FGT # diag test application ipsmonitor
IPS Engine Test Usage:
1: Display IPS engine information
2: Toggle IPS engine enable/disable status
3: Display restart log
4: Clear restart log
5: Toggle bypass status
6: Submit attack characteristics now
10: IPS queue length
11: Clear IPS queue length
12: IPS L7 socket statistics
13: IPS session list
14: IPS NTurbo statistics
15: IPSA statistics
97: Start all IPS engines
98: Stop all IPS engines
99: Restart all IPS engines and monitor
If you need stop the IPS process use the option 98.
Regads,
Sérgio Souza
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1632 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.