Fortinet Fortigate Internet Traffic Halts – CPU At 99%

Ran into a wonderful situation yesterday on a Fortinet Fortigate 100C where, every hour on the half hour the internet traffic would cease passing through the router.

The solution was to reboot the firewall.

Turns out, there was a bug in the 4.2 firmware (4.0 build 0272) with the NIDS signature. I believe it was triggered when our Trend Micro Worry Free Business Security Advanced server would try to update (hence the every hour on the half hour).

This was diagnosed via the CLI command:

Diag Sys Top 1

Let that run for a few seconds, then hit CTRL-C to stop.

IPSEngine was using 90+ % CPU (the first decimal number in the 2nd to last column is CPU usage, the last is memory usage)

Fortinet support sent me the newer NIDS signature manually, which should be automatic later today.

Fun times.