FortiOS 6.2.3 - high Memory, low CPU, DNS Filter unreachable
Hi everyone,
FG61E active-active HA
Since v.6.2.3 we have very high memory usage. The Fortigates go into conserve mode all the time and i can't get the memory any lower than 77%. I disabled unrequiered features, switched some policies from proxy-based to flow-based, reduced the session timers, logging etc. Nothing helps. The memory overflows while the CPU runs on <5% most of the time. I have a customer with about 20x FG 30E. Some of these do nothing but IP-Sec VPN and nothing else yet but the memory there is also on 68% while the CPU is <5%. What can I do to reduce my memory usage? Or is it a firmware issue? There were problems with the memory management in v6.2.0 and 6.2.2 in the past.
Also I noticed that the FortiGuard DNS Filter Server is unreachable in v6.2.3. I configured the DNS Filter IP from v.6.2.2 (on which it works) and it doesn't work on v6.2.3 either. I already have a case open with fortinet about the DNS Filter issue.
-Jannik