Skip to main content
dnetcrawler
New Member
April 1, 2026
Question

6300F FPC ran out of memory after 16 days – kernel slab leak? FortiOS 7.6.6

  • April 1, 2026
  • 4 replies
  • 284 views

Has anyone seen this on a 6300F or 6500F? Looking for a cleaner fix than rebooting the FPC.

Specifically wondering:
1. Is this a known bug in 7.6.x with a fix in a later build?
2. Is there any way to reclaim kernel slab memory without rebooting the FPC?


We had an incident last night where FPC1 on our 6300F started dropping packets after about 16 days of uptime. The other 5 FPCs were completely fine. Rebooted FPC1 and everything came back to normal immediately.

 

The log message we saw:
fw_forward_handler line=788 msg="The system is in extreme-low-memory state. Drop the packet."

When we dug into it with diag hardware sysinfo memory we found the problem — SUnreclaim on FPC1 had grown to 22GB while every other FPC was sitting at around 600MB. MemFree on FPC1 was down to 2%.

 

At incident:
FPC1 - SUnreclaim: 22,029,000 kB :warning: - MemFree: 692,292 kB (2%)
FPC2 - SUnreclaim: 626,632 kB - MemFree: 21,902,960 kB (66%)
FPC3 - SUnreclaim: 621,352 kB - MemFree: 21,918,292 kB (66%)
FPC4 - SUnreclaim: 625,980 kB - MemFree: 21,930,484 kB (66%)
FPC5 - SUnreclaim: 620,464 kB - MemFree: 21,918,412 kB (66%)
FPC6 - SUnreclaim: 632,240 kB - MemFree: 21,928,744 kB (66%)

 

After FPC1 reboot:
FPC1 - SUnreclaim: 506,964 kB
FPC2 - SUnreclaim: 653,604 kB
FPC3 - SUnreclaim: 616,284 kB
FPC4 - SUnreclaim: 622,384 kB
FPC5 - SUnreclaim: 620,600 kB
FPC6 - SUnreclaim: 617,336 kB

 

Since SUnreclaim is non-reclaimable kernel memory this doesn't show up in process monitoring at all — we only caught it by running diag hardware sysinfo memory across all slots when the drops started.

 

For now we're monitoring daily with:
diag hardware sysinfo memory | grep -E "Slot|SUnreclaim"

 

And will proactively reboot any FPC that goes over 5GB before it becomes a problem. The slot reboot is non-disruptive so it's manageable, just not ideal.

 

Platform: FortiGate 6300F
FortiOS: 7.6.6 build 3652 (GA)

```

4 replies

OktaRianzani
Visitor III
April 1, 2026

Just adding some field insight here — not claiming this fully resolves the issue.

 

This looks more like a kernel (slab) memory growth on a single FPC rather than a userspace/process leak:

  • Only FPC1 was affected
  • SUnreclaim grew abnormally (~22 GB) while others stayed normal
  • Traffic drops started when memory became critically low
  • Rebooting the FPC immediately reset the condition

Since SUnreclaim is unreclaimable kernel memory, it typically won’t show up in process monitoring and cannot be freed without restarting the FPC.

 

I couldn’t find a clear public bug reference for this in 7.6.6 release notes, but the behavior is suspicious and could indicate a platform-specific bug.

 

For now, your approach makes sense:

  • Monitor SUnreclaim per FPC
  • Proactively reboot the affected slot before it reaches critical levels

I would recommend opening a TAC case to confirm whether this is a known internal issue or fixed in a later build.

 

Regards

dnetcrawler
New Member
April 1, 2026

Update – Day 2 monitoring

FPC2 is already showing the same pattern. Less than 24 hours after rebooting FPC1, FPC2 SUnreclaim has jumped from 653MB to 1.4GB while every other FPC remains stable.

 

SUnreclaim today vs baseline:
FPC1 - Baseline: 506,964 kB / Today: 511,452 kB / Growth: +4,488 kB :white_heavy_check_mark: normal
FPC2 - Baseline: 653,604 kB / Today: 1,432,712 kB / Growth: +779,108 kB :warning:
FPC3 - Baseline: 616,284 kB / Today: 541,120 kB / stable :white_heavy_check_mark:
FPC4 - Baseline: 622,384 kB / Today: 547,860 kB / stable :white_heavy_check_mark:
FPC5 - Baseline: 620,600 kB / Today: 540,296 kB / stable :white_heavy_check_mark:
FPC6 - Baseline: 617,336 kB / Today: 541,024 kB / stable :white_heavy_check_mark:

 

FPC1 is completely clean after the reboot. FPCs 3-6 are stable. Only FPC2 is leaking.

Worth noting that FPC2 is the primary FPC blade on this unit. The primary FPC handles additional tasks like ICMP and certain session types that other FPCs don't — not sure if that's relevant but it seems significant that the leak is now on the primary.

 

At this rate FPC2 will hit critical levels in roughly 10-12 days.

dnetcrawler
New Member
July 5, 2026

We figure out this was not related to the VIP, but an actual memory leak on 7.6. We moved to 7.4 and no problems at all, same config.

We would not recommend anyone to run 7.6 on these specific appliances!

HarryTran
Staff
Staff
July 6, 2026

Hi ​@dnetcrawler,

Based on the description, the FortiGate 6300F may be running into known bugs 1242828 and/or 1244720, which are listed in the FortiOS 7.6.6 release notes.
Known issues | FortiGate / FortiOS 7.6.6 | Fortinet Document Library

The reported symptom appears related to high memory usage on the FPC, with SUnreclaim increasing significantly until the system reaches an extreme low-memory state and starts dropping packets.

Regards,

Harry

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!