Skip to main content
npaiva
Staff & Editor
Staff & Editor
September 16, 2025

Technical Tip: ASLR on FortiGate and memory usage concerns.

  • September 16, 2025
  • 0 replies
  • 1513 views
Description This article describes ASLR. ASLR stands for Address Space Layout Randomization, a computer security technique that randomizes the memory addresses of key areas of a running program, such as executables and system libraries. By randomizing these memory locations at each launch, ASLR makes it significantly harder for attackers to successfully execute code injection or buffer overflow attacks, which often rely on knowing the fixed addresses of these components to exploit vulnerabilities.
Scope FortiGate.
Solution

ASLR is a non-configurable kernel-level security hardening feature introduced progressively in FortiOS. It enhances protection against memory-based exploits but consumes additional RAM due to randomization overhead.


This feature has an impact on memory usage, therefore low ends models with 4GB of RAM have only partial ASLR implementation, which already has an impact of 7% when idle. This setting cannot be changed or disabled:

 

Memory increase on low-end models with 4 GB RAM and ASLR - FortiOS 7.4.8 release notes.

Appliances with 8GB or more have full ASLR implemented.

 

This feature does not run on low end appliances with 2GB of RAM.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.