type
status
date
summary
tags
category
URL
password
slug
icon
This is a quick reference on how to configure an Automation Stitch for CPU threshold on a Fortigate.
Please note that I configured this on Fortigate Firmware 6.2.7. You will also need to ensure that SMTP is setup on the Fortigate.
1. Configure CPU Threshold
This is the value at which point the Fortigate will generate a log for CPU usage.
2. Configure Automation Stitch
2.1 GUI
2.1.1 Create New
This can be found under Security Fabric / Automation
2.1.2 Select Trigger for Email
In this case CPU Usage Statistics which is under FortiOS Event Log option.
2.1.3 Select Email
Add the email address that you want the alerts sending to.
2.2 CLI
Configure the SMTP server email configured in step 1 as the “email-from”
4. Test
In order to test this you will need to generate enough traffic to peak the CPU past the minimum 50% . You could use a network stress tester to achieve this. Adding logging, UTM and turning off the CPU offloading on the firewall policy will increase CPU usage.
Thank you for reading and please feel free to leave any feedback.
- Author:NetSec
- URL:https://blog.51sec.org/article/7eef7d53-5112-4b9b-978d-7b47e78ecc1f
- Copyright:All articles in this blog, except for special statements, adopt BY-NC-SA agreement. Please indicate the source!