Kernel and System conserve mode thresholds
- October 30, 2017
- 4 replies
- 13425 views
Hi guys,
I need a clarification about the Kernel and System conserve mode thresholds. According to the NSE4 course, here you are these thresholds:

1. The ambiguity is when the Fortigate has a memory <= 1GB, where the thresholds are the same. What happens if I have a Fortigate with a memory between 512 MB and 1 GB and I have reached 81% of my memory? The Fortigate will enter Kernel or System conserve mode? I can't answer this question from the above slides.
2. What mode is more aggressive? I would say is Kernel since any proxy inspection is bypassed and you can't do any configuration changes, while the system mode at least you can somewhat configure the behaviour with the "av-failopen" command. If I am right and Kernel is more aggressive, it makes sense the Fortigate goes first into system conserve mode (less aggressive) and if the memory usage keeps growing then into kernel conserve mode (more aggressive). But the above thresholds are also ambiguous since taking some numbers you can notice a Fortigate would enter first in the Kernel mode and later in the System mode. Let's say a Fortigate with 512 MB, when the Fortigate has 102.4 MB left (<20%) would enter the Kernel mode, and if its memory usage keeps growing and has 40 MB left, then it would enter the System conserve mode.
What do you think about these two points?
Regards,
Julián
