Hi community,
I have a FGT VM with one CPU (of 4) that reaches 100% peaks, while the others are idle. Due to the characteristics of the traffic I believe this is "normal" (there is a fixed session between 2 IPSec hosts that always use the same source IP/port and the same destination IP/port with over 800Mbps throughput, which is handled by a single CPU, while the other ones share the rest of the load). I believe this CPU is dropping packets because it can't handle the total amount of traffic, and I would like to demonstrate this to the customer, but how?
I can easily:
but how do I relate the session from the first command to the CPU status from the second command? How do I show that there is packet loss?
Could you suggest some commands that highlight these aspects?
thanks guys,
Angelo
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Angelo
I think you should be able see packet loss if you use "fnsysctl ifconfig" and look into the tunnel interface and the WAN interface's output (errors, dropped).
You may also check if there is packet loss on SD-WAN (if applicable), with "diagnose sys sdwan health-check".
Following tech tip may also help to distribute IPsec across multiple cores.
Hope it helps.
Hi AEK,
from your debug command I didn't find a direct session - CPU relationship but the information on the KB is very useful can help me with my problem... so good to know.
Thank you for your answer
You can also check the doc to troubleshoot the high cpu issue : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Debugs-for-troubleshooting-high-CPU-Issues...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1066 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.