Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

ips performance

hi folks, just want to clarify could IPS affect the system resources (memory/cpu) even it doesn't applied to any policies? 

Fortigate Newbie

Fortigate Newbie
2 REPLIES 2
emnoc
Esteemed Contributor III

if you have no sensor/profiles and nothing defined with regards to IPS, than most likely the answer is now. You will see a few running process for IPS but this  process always runs

 

e.g

ipsmonitor/helper/ipsengine

 

I don't think you can completely disable these.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Fullmoon
Contributor III

hi emnoc,

 

thank you for response I appreciate it.

Here's the case, installed FGT 90D to one of my client roughly 50-60 computers,its more on outgoing traffic (http/s), including 3 server visible from outside thru VIP.

I noticed that the memory spiking (up/down) to 100%, cpu spikes to 30-50% randomly.I applied the utm features Web Profile and App Control that blocks p2p,games,botnet,proxy. to a single outgoing policy.

I requested one of the TAC to access the said unit to fully investigate whats going on behind my customer unit and he told me that the behavior of the said box is normal and it was caused by IPS.

I am aware that App Control uses IPS but it can give huge impact? 

 

Fortigate Newbie

Fortigate Newbie
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors