Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tindrli
New Contributor

High memory utilization on Fortigate 80E

Could someone share his/her data on memory utilization on Fortigate 80E with SSL inspection, AV, IPS enabled?

Is it possible to list which IPS signature is using the most resources?

I'm using FortiOS 6.0.4 with two 80E in cluster (A/P). My memory usage is 80-85% and quite often my boxes go in conserve mode. I did all the suggested memory performance tweaking and I also created script for restarting IPS engine. When i restart IPS engine memory drops to 60-ish %. I'm wondering if this is normal behavior for this box with all the profiles enabled and 50-60 users on the network.

4 REPLIES 4
ede_pfau
SuperUser
SuperUser

There is no way to list the most-used IPS signatures.

 

But, it's not so much the signatures in use but the signatures the FGT has to check...if you enable all available signatures the FGT will really have to work a lot. And IPS is memory-intensive.

 

My advice:

create UTM profiles for different user / host groups (clients, servers, guest WiFi). Select IPS signatures according to the threats you expect for each group. For instance, you will not check Linux signatures if all of your hosts run Windows...


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Tindrli

That's what I thought, I already selected Windows OS and changed severity to med, high, critical.

i never experienced this myself, I only know what client tells me. What should i monitor in order for slave unit to take over when primary fails in this case? I have a cluster of two Fortigates here in A/P mode.

Ashik_Sheik

You can only do the automatic failover by setting the monitor inetrface not by service or memory .

May b other experts can comment on this .

Ashu 

 

Ashu
Tindrli

I know that part, but since I never experienced this myself I was wondering if inside interface becomes unresponsive for example. If yes, maybe I could setup a SLA tracker to it. This is very difficult to test in the lab since I can't make that much traffic in order for firewall to go in conserve mode.

Labels
Top Kudoed Authors