Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dwear
New Contributor

IPSmonitor process High Memory

We have a cluster of 60Es 6.0.6 running fairly generic services. I notice today that they are running at roughly 75-77% Memory. They are currently processing roughly 2500 sessions. I noticed in the diag sys top that there are 6x ipsmonitor processes using around 20-23% memory. I tried killing the processes, but they came back with the same memory usage. I tried reducing the IPS usage by creating policies to allow DNS and all our O365 traffic without IPS, as well as reducing the IPS profile down to only relevant attacks. Any thoughts?

2 REPLIES 2
seadave
Contributor III

I'm having the same issue on a small FWF60E at home.  We use a 501E cluster at work with no problems. FOS 6.

0.8  The smaller gates historically have these memory issues so you need to be very specific about the services you enable.  I found in my IPS policy that I had a few old signatures that showed as invalid.  I've removed those.  Not sure if that will help, but you might check your policies for orphans like that.  This sometimes occurs after an update.  Also look under Rate Based Signatures if you have any of those enabled.  If you see any that are just listed as 5 digits they are no longer valid.  Disable them, apply the policy and they will be gone upon refresh.

tanr
Valued Contributor II

Hey seadave,

 

Were the old invalid signatures referenced in the IPS Signatures overrides, or were they just in the general list?  If just in the general list, how did you find them?   And Happy New Year!

Labels
Top Kudoed Authors