Dear colleagues, good afternoon.
In this post I seek information on how to perform a configuration in Fortigate where I can prevent the equipment from reaching 80% CPU usage. This fact has occurred with some frequency lately. I would like advice on how to proceed in this situation. Thank you very much in advance for your attention and understanding.
Thank you msanjaypadma for the reply on my request.
No idea if this will be helpful...but what's wrong with a high CPU usage? I've witnessed many events when the CPU spiked to 100%, usually when new AV/IPS signatures were downloaded and mangled. The effect on ongoing traffic was zero. IMHO CPU is used for session setup, management traffic (SNMP etc.) and the GUI. Best practise hints to configure the policies such that a high percentage of traffic is offloaded to the SP(s). You can observe that in the Interface Bandwidth widget. For me, I've paid for the CPUs, let them sweat at 100% for 24/7, no issue.
(of course, yes, it might indicate an issue if it stays that high for a prolonged period)
Totally different from this, a high memory usage will put the FGT in danger, or, in other words, it indicates an unhealthy condition. In the worst case, lack of memory will stall all services and throughput. I guess that's why there is a SNMP trap now in recent OS versions when the upper limit is reached.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.