Hot!FortiGate 100E CPU Usage maxes out when downloading

Author
ITHRBruce
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/04/04 01:16:16
  • Status: offline
2018/04/04 03:40:12 (permalink)
0

FortiGate 100E CPU Usage maxes out when downloading

Hi,
 
We have been using a FortiGate 100E for about 6 months or so without incident. We have a 1GB pipe out to the net and have around 60 users here. We are on firmware v5.4.5, build 6225 (GA).
 
Recently we have noticed that CPU Usage starts to max out if anyone does even a moderate download. My ISP manages the firewall as I am not a firewall expert. They have contacted Fortinet and at their request sent over usage logs a few times, but without a solution being offered. My ISP have made a lot of changes and done a great job to reduce the scanning footprint which seems to cause this, and this has made things run much, much better. However we can still get a bad peak, albeit smaller. I myself downloaded a 2GB file from a reputable website (Veritas), in about 8 mins, and the CPU Usage peaked at about 60%. While this was nowhere as bad, why should it go so high when the device is capable of handling thousands of connections? It seems the scanning is quite aggressive, or way too many resources are being allocated to it.
 
And of course I am concerned if just a few users started a large download. I have seen it go up when someone starts up their email and downloads a few hundred meg, all very legit stuff. Very perplexing. Anyone have any idea as what could be going on here?
 
Many thanks.
 
#1

11 Replies Related Threads

    romanr
    Platinum Member
    • Total Posts : 903
    • Scores: 28
    • Reward points: 0
    • Joined: 2004/06/08 08:29:56
    • Location: Vienna/Austria
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 04:11:43 (permalink)
    0
    Hi,
     
    first of all, you run the shipment firmware, which is somehow out of the normal support tree and you should really consider upgrading your box to 5.4.8.
     
    If you want to reach speed in the area of ~1GBit with a 100E -> you should consider running the firewall in flow mode - or at least use flow mode profiles on your high speed/volume policies.
     
    Br,
    Roman
    #2
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 04:15:08 (permalink)
    0
    Thanks I will ask my ISP if this can be enabled.
    #3
    Hosemacht
    Bronze Member
    • Total Posts : 25
    • Scores: 1
    • Reward points: 0
    • Joined: 2017/04/18 04:06:13
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 04:25:26 (permalink)
    0
    Hey there,
     
    first of all we need to know witch features are used on the Internet facing policy.
    Yes the Fortigate 100E has 7,7 Gbit Firewall throughput but when it comes to ssl inspection it falls down to 190Mbit.
    You can check this in the datasheet : https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_100E_Series.pdf.
     
    Unfortunately i guess your Internet is simply too fast :)
     
    PS.: ill recommend you to upgrade to 5.4.8 and try to tune you security Profiles
    #4
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 04:46:55 (permalink)
    0
    Thanks Giraffe guy, we'll look at that.
    #5
    ede_pfau
    Expert Member
    • Total Posts : 5585
    • Scores: 376
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 05:02:17 (permalink)
    0
    Any chance you connect to WAN via PPPoE?

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #6
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 05:05:43 (permalink)
    0
    Not sure, would have to check with my ISP who manage it. If so, what action would you recommend they take? Thanks.
    #7
    ede_pfau
    Expert Member
    • Total Posts : 5585
    • Scores: 376
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 05:16:28 (permalink)
    0
    Background: the smaller FGTs have a known weakness if they have to sustain a PPPoE connection beyond 100 Mbps. The workaround/solution is to use a standalone modem instead (pass-through).
    Just a thought. Your setup might well be completely different.

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #8
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/04 05:21:47 (permalink)
    0
    Interesting, although I haven't seen those speeds when I've been monitoring. Thank you.
    #9
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/10 08:17:17 (permalink)
    0
    Hi,
     
    We have now had the firewall's firmware upgraded to the latest version, 5.4.8. So far, so good.
    However, when some of my developers try to access a website such as https://abc123.domain.com/ by browsing to just https://abc123/ (abc123 has been noted in the local hosts file with its IP address) they can no longer hit that web site and instead get the firewall's standard access denied error message.
     
    This was fine before the firmware upgrade. We can get around it by setting an 'allow' rule for the whole FQDN but my guys have about 90 test domains that they want to hit by just specifying the sub-domain.
     
    Any idea what setting can be changed to accommodate this usage?
     
    Thanks!
     
    #10
    ede_pfau
    Expert Member
    • Total Posts : 5585
    • Scores: 376
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/15 04:45:29 (permalink)
    0
    Awkward. This is a problem with DNS. You haven't stated if you resolve via the FGT or some internal server. I cannot imagine (yet) how a firmware update could influence the DNS to not resolve if it worked before.
    Is this protocol related? Can you ping both 'abc123' and 'abc123.domain.com', or will the short form fail here as well?

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #11
    ITHRBruce
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/04 01:16:16
    • Status: offline
    Re: FortiGate 100E CPU Usage maxes out when downloading 2018/04/16 00:38:36 (permalink)
    0
    Hi, thank you for your reply.
    The sub-domains aren't set up on DNS, although the domains are. DNS resolution is performed on the firewall, although sub-domain resolution is down to the users modifying the hosts file whenever they needed to hit those sub-domains. My colleagues had set up about 90 of these. They were all accessible prior to the update but not now. The only way to make them work so far is to set an 'allow' rule on the firewall.
    Thanks.
     
    #12
    Jump to:
    © 2018 APG vNext Commercial Version 5.5