- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
High NIC usage
Ive noticed over the past few installs, 5.4 and 5.2.5, that after installing, and even after a reboot, my NIC shows it is getting data at 8MB/sec. I have to shutdown forticlient and sometimes reboot, then will go to normal.
I first noticed this in my lab environment after installing EMS and pushing out to 3 servers, it eventually brought down my entire network and killed CPU and NIC traffic, i had to power off two esx hosts and my SAN, switch and start fresh.
Since then, i have noticed this on clients, mostly they are Windows 10 installs, yet there are a few Windows 7 pc's i notice this on.
Anyone else having related issues or possibly know?
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you know what IP address it's sending traffic? I want to know if it is downloading AV signatures.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It appears to be the local IPv4 address, and I will have to see if I can do some more digging when it does occur, sometimes it happens a day or two later after a I boot up a pc, it will then just hang and CPU and NIC go berserk, there is a Host Service system proc that is going, I will have to get a screen shot for you so you can see exactly, but either a reboot, or killing that service seems to help.
I will work on getting pics and more details, it appears however that its not trying to grab AV signatures, yet just causes a broadcast storm that brings things down.
Stay tuned...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It will be helpful to identify the type of traffic.
You case reminds me a traffic storm in my network, which turned out to be some IGMP broadcast.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@micahawitt, did you end up getting to the bottom of your issue? I'm seeing the identical situation - end result is a broadcast storm that brings the network down.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@rossco
I wish I could say I have, been still no able to get to the bottom of it. I will say, that I have been using 5.2.5 lately with no issues on my PC's. So perhaps something with 5.4.0 or maybe even a silent update.
I still have done nothing with EMS lately either since that was the killer that started it all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know that's a work around, but I find it unacceptable that a software package is causing broadcast storms.
Alan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Chris,
Since b788 worked so well for me, would it be wise to deploy this across all of our workstations, or is there a future release for FortiClient coming out soon ?
Alan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, Alan,
FortiClient 5.4.1 release is scheduled for end of March. It's better to wait for a release build.
BTW, it's the application firewall which causes the issue. If you don't need it, you can disable this feature to work-around it for now.