Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
joel_b
New Contributor

Policies take long to load

Hi we have over 2000 policies on our Fortigate 3600 running 5.0.5. It takes a couple of minutes for the policies to load in the GUI. Does anyone know of a tweak that can speed this up a bit please? Is anyone else having this issue? Thank you.
Best Regards, Joel B | CCNA, FCNSA
Best Regards, Joel B | CCNA, FCNSA
7 REPLIES 7
emnoc
Esteemed Contributor III

What version of broswer?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
joel_b
New Contributor

I' ve tried IE 11, Chrome v32 and Firefox v26 but the policies still take a couple of minutes to load.
Best Regards, Joel B | CCNA, FCNSA
Best Regards, Joel B | CCNA, FCNSA
emnoc
Esteemed Contributor III

HTTP or HTTPS ( I' m assuming HTTPS ) ? fwiw: I just loaded 1430 policies in a 3600C running 5.0.3, firefoix 26.0 on MACOSX. Not blazing fast, but it took just under 35secs from kicking the firewall policies tab. CPU runs at a constant 65% on this device, wth no UTM, maybe 12 active vpns. suggestions; try looking at diag sys top and check how many running process. try reducing unneeded services check access from 2 or 3 client machine to ensure it' s not your browser or host that' s screwing up open a ticket with fortinet support fwiw: unlesss you have a need to run 5.0.5 , I would not run it due to it' s being quite newer. My immediate thoughts for the slowness might be in the http daemon. So you can try to kill it and let it restart diag sys kill -9 <proc id>

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
joel_b
New Contributor

Thank you sir. I' ll try your suggestions and let you know how it goes.
Best Regards, Joel B | CCNA, FCNSA
Best Regards, Joel B | CCNA, FCNSA
joel_b
New Contributor

Oh and yes it is https access. When we were running 5.0.4 we ran into high CPU and memory utilization issues but we had UTM features enabled. Fortinet support said it was Bug ID 0220191 - high CPU usage on urlfilter deamon after the cache is full. The fix was to update to 5.0.5. THe update to 5.0.5 fixed the high cpu and memory utilization (CPU averages less than 10% now) but the problem with the policies taking long to load persisted. Everyone on the security team is having the same issue with the policies. We tried the Fortimanager and the policies loaded much faster on that ... but the trial period ended on that and we did not get to keep it ...
Best Regards, Joel B | CCNA, FCNSA
Best Regards, Joel B | CCNA, FCNSA
joel_b
New Contributor

Fortinet support said that this is a bug (ID 0213699) that will be fixed in 5.0.6 ...
Best Regards, Joel B | CCNA, FCNSA
Best Regards, Joel B | CCNA, FCNSA
Jordan_Thompson_FTNT

Fortinet support said that this is a bug (ID 0213699) that will be fixed in 5.0.6 ...
Correct. Note that performance will be slightly slower on Chrome + HTTPS when using the default unsigned server certificates as Chrome ignores caching in this setup.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors