Fortigate memory exhausted in seconds - 99% and not reacting to anything
Hi folks,
we have got a Fortigate 60F for 2 years now. It is running on FortiOS 7.0.6. Out of nowhere (about a week ago) it started to go in conserve mode. And even worse - after hitting 99% of mem usage, it does not react to anything. If it goes up to 99% you also cant use the cli anymore.
This also happened at night, where only servers are online.
About 3-10 Minutes after hitting the 99% mem, the usage drops again (to normal (for us) 63%) and it runs without troubles for hours.
It was a pain in the .... to investigate where it is coming from.
At least I figured out, that the problem is triggered by servers of our DMZ. (after the FGT starts to increase mem usage I disconnected all Ports and reconnected them one by one. LAN, WAN1, WAN2 does not trigger it, but reconnecting DMZ does).
After that I shut down all not essential servers running at DMZ. After the shutdown, the problem does not reappear again.
At the moment, it looks like that something is going on on the servers which are shut down at the moment. Something which kills the Forti.
I cannot see any suspicious traffic in the logs.
So, how should I approach this problem. Do you have any tipps? What could trigger the Fortigate that way, that the mem-usage goes up from 65% to 99% within 30 secs?
Thanks!
