Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
micahawitt
New Contributor III

High NIC usage

Ive noticed over the past few installs, 5.4 and 5.2.5, that after installing, and even after a reboot, my NIC shows it is getting data at 8MB/sec.  I have to shutdown forticlient and sometimes reboot, then will go to normal.

 

I first noticed this in my lab environment after installing EMS and pushing out to 3 servers, it eventually brought down my entire network and killed CPU and NIC traffic, i had to power off two esx hosts and my SAN, switch and start fresh.

 

Since then, i have noticed this on clients, mostly they are Windows 10 installs, yet there are a few Windows 7 pc's i notice this on.

 

Anyone else having related issues or possibly know?

 

Thank you

17 REPLIES 17
alantz

Thanks Chris. I can probably do that. I will probably just hang tight for the 5.4.1 release at this point, March is right around the corner.

 

--Alan

 

 

Chris_Lin_FTNT

Could you try Windows build 788?

 

https://www.dropbox.com/sh/cb0j4pxw1f8nq84/AABHzZW1bpx1VjzYAmiK00S9a?dl=0

 

It has some fix for Application FireWall.

 

Thanks.

micahawitt

I will test this build tonight and let you know.

 

Thank you

alantz

I just had the same sort of issue on our network with FortiClient 5.4. Whenever firewall is enabled through custom FortiClient XML, cisco router starts heavy IGMPv2 traffic. Ticket number is 1606251. Never noticed this with 5.2.3.

 

Alan

 

 

Chris_Lin_FTNT

Alan,

 

It's good to try b788, too.

alantz

I have narrowed it down to the client triggering massive IGMPv2 messages from the router to the multicast address of 224.0.0.1. If I disable the FireWall section in my custom XML file the broadcast storm stops. Very odd. I have not tried b788 yet. Will do that today.

 

Alan

 

alantz
New Contributor

Very interesting, when installing 7.88 it installed fine and I noticed windows updates were available. The pc's then got a warning about detecting malware. It was remnants of CryptoWall we had in the spring. Once I cleaned out the users temp folder and the system temp folder the malware warning went away and the updates installed. I am seeing normal network activity now.

 

Alan

 

 

alantz
New Contributor

W32/Filecoder.EM!tr was the virus found with realtime protection. It found restore_files_geeuh.html in a c:\windows\assembly folder. Once I emptied the temp folders this went away.

 

Alan

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors