Hot!IPS Engine Running at 95%-99% Constantly

Author
MikeMo
Silver Member
  • Total Posts : 74
  • Scores: 4
  • Reward points: 0
  • Joined: 2009/03/05 16:07:14
  • Status: offline
2010/06/02 21:21:08 (permalink)
0

IPS Engine Running at 95%-99% Constantly

I am running version v4.0build0194 (MR1 Patch 3) and IPS Engine 1.00164. As of Wednesday last week we started seeing our CPU spike to over 95% and cause an interuption of services. After several days of providing logs and debug information to Fortinet the best possible answer we received was to restart the ipsengine services to resolve the issue and/or bypass the ipsengine entirely.

They now defined it as a bug #125279. Just wanted to give everyone a heads up.
#1

7 Replies Related Threads

    ejhardin
    Gold Member
    • Total Posts : 438
    • Scores: 12
    • Reward points: 0
    • Joined: 2007/09/22 20:30:02
    • Location: Pacific Northwest
    • Status: offline
    RE: IPS Engine Running at 95%-99% Constantly 2010/06/03 08:57:21 (permalink)
    0
    Thanks... I have heard that 164 still has a bug in. I have not seen anything yet. Would you mind sharing a little more info? What box are you using? Were you on the same firmware when 164 was installing or have you upgraded? When does the spike happen while modifing the system or was it randomly on its own. I assume that tech support kill the service with the kill 11 command, did they say what process was the issue?
    #2
    MikeMo
    Silver Member
    • Total Posts : 74
    • Scores: 4
    • Reward points: 0
    • Joined: 2009/03/05 16:07:14
    • Status: offline
    RE: IPS Engine Running at 95%-99% Constantly 2010/06/03 20:24:01 (permalink)
    0
    310B is the only model I have seen the problems on. The IPS engine was current when we started seeing the problem. The spikes would happen at random periods of time but according to support it looks like the IPSengine was crashing every 30 mins or so. CPU didn' t spike everytime but it was spiking like 2-3 times a day and staying there. The IPSengine process is the issue.
    #3
    ejhardin
    Gold Member
    • Total Posts : 438
    • Scores: 12
    • Reward points: 0
    • Joined: 2007/09/22 20:30:02
    • Location: Pacific Northwest
    • Status: offline
    RE: IPS Engine Running at 95%-99% Constantly 2010/06/04 09:36:40 (permalink)
    0
    Thanks... If you hear more please share.
    I was asking about the process because when the IPS engine spike in CPU or memory it really could be because of a different process. The IPS engine is like the GOD of all other process. Most of the other process needs the IPS engine to do their job. If you do a diag kill 11 it will print a crash log. If you read the crash log it will tell you the process that were causing the issue.
    #4
    MikeMo
    Silver Member
    • Total Posts : 74
    • Scores: 4
    • Reward points: 0
    • Joined: 2009/03/05 16:07:14
    • Status: offline
    RE: IPS Engine Running at 95%-99% Constantly 2010/06/22 13:52:24 (permalink)
    0
    I believe it was actually the IPSMonitor process failing. However, we have since upgraded to 4.0MR2P1 and the problem still exists. I think the bug has carried over.
    #5
    g3rman
    Platinum Member
    • Total Posts : 598
    • Scores: 12
    • Reward points: 0
    • Joined: 2008/04/30 08:51:15
    • Status: offline
    RE: IPS Engine Running at 95%-99% Constantly 2010/07/11 18:07:52 (permalink)
    0
    Same thing here. We were running ok until a few weeks ago and now I keep getting paged about high CPU utlization. Seems to affect a number of platforms, including 60B and 800.

    A Real World Fortinet Guide
    Configuration Examples & Frequently Asked Questions

    http://firewallguru.blogspot.com
    #6
    T3
    New Member
    • Total Posts : 1
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/06 13:15:31
    • Status: offline
    Re: RE: IPS Engine Running at 95%-99% Constantly 2018/04/06 13:24:46 (permalink)
    0
    Our firewall stays between 99 and 100%, only when we turn off the ips it lowers the CPU consumption. How important is keeping the ips on? Fortigate 60C Firmware 5.2.11
    #7
    ujnetsec
    New Member
    • Total Posts : 11
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/04/16 00:02:06
    • Status: offline
    Re: IPS Engine Running at 95%-99% Constantly 2018/04/16 01:15:39 (permalink)
    0
    IPS Engine Running at 95%-99% Constantlyim expiriencing a similar problem, whereby one of our VDOMs in a 3000D FW with connects +- 50k users, max sessions is +-400k sessions, the CPU spikes at around 9am every morning when everyone is back at work, and this affects our filtering, but as soon as we disable SSL Certificate inspection, the CPU goes back to normal. SSL is configured to inspect only 443. what could the issue be?
    #8
    Jump to:
    © 2018 APG vNext Commercial Version 5.5