Could someone share his/her data on memory utilization on Fortigate 80E with SSL inspection, AV, IPS enabled?
Is it possible to list which IPS signature is using the most resources?
I'm using FortiOS 6.0.4 with two 80E in cluster (A/P). My memory usage is 80-85% and quite often my boxes go in conserve mode. I did all the suggested memory performance tweaking and I also created script for restarting IPS engine. When i restart IPS engine memory drops to 60-ish %. I'm wondering if this is normal behavior for this box with all the profiles enabled and 50-60 users on the network.
There is no way to list the most-used IPS signatures.
But, it's not so much the signatures in use but the signatures the FGT has to check...if you enable all available signatures the FGT will really have to work a lot. And IPS is memory-intensive.
My advice:
create UTM profiles for different user / host groups (clients, servers, guest WiFi). Select IPS signatures according to the threats you expect for each group. For instance, you will not check Linux signatures if all of your hosts run Windows...
That's what I thought, I already selected Windows OS and changed severity to med, high, critical.
i never experienced this myself, I only know what client tells me. What should i monitor in order for slave unit to take over when primary fails in this case? I have a cluster of two Fortigates here in A/P mode.
You can only do the automatic failover by setting the monitor inetrface not by service or memory .
May b other experts can comment on this .
I know that part, but since I never experienced this myself I was wondering if inside interface becomes unresponsive for example. If yes, maybe I could setup a SLA tracker to it. This is very difficult to test in the lab since I can't make that much traffic in order for firewall to go in conserve mode.
User | Count |
---|---|
2677 | |
1412 | |
810 | |
703 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.