Created on 12-15-2024 02:08 PM Edited on 12-16-2024 07:54 AM By Jean-Philippe_P
Description | This article describes a known issue where FortiGate Devices with 4GB memory may enter conserve mode when certain IPS or APP control features are enabled. |
Scope | FortiGate. |
Solution |
FortiGate Devices with 4GB memory like the FortiGate100F/101F (Hardware Revision: Rev1) may enter conserve mode when certain IPS or APP control features are enabled.
FortiGate-100F# get hardware status Model name: FortiGate-100F ASIC version: SOC4 CPU: ARMv8 Number of CPUs: 8 RAM: 3614 MB EMMC: 3662 MB(MLC) /dev/mmcblk0 Hard disk: not available USB Flash: not available Network Card chipset: FortiASIC NP6XLITE Adapter (rev.) Hardware Revision: Rev1
FortiGate-100F# diagnose sys top-mem 50
FortiGate-100F # get sys perf status Memory: 3701376k total, 3174480k used (85.8%), 312896k free (8.5%), 214000k freeable (5.7%)
logid="0100022815" type="event" subtype="system" level="notice" vd="root" logdesc="Scanunit loaded AV Database" action="update" msg="scanunit=manager pid=1204 loading AV database successful"
FortiGate-100F # diag sys top-all 2 100 Run Time: 0 days, 0 hours and 20 minutes 25U, 0N, 0S, 75I, 0WA, 0HI, 0SI, 0ST; 3614T, 643F ipshelper 263 R 99.9 3.5 4 wad_ips 1338 R 99.5 1.8 2 bcm.user 133 S < 2.9 0.5 1 newcli 1333 S 1.4 0.7 0
FortiGate-100F # diagnose sys top-mem 250 ipshelper (263): 369914kB wad_ips (1338): 195507kB
ipshelper is part of the IPS engine and wad_ips is WAD's ips/appctl database builder
This issue is resolved in FortiGate v7.6.2 Firmware and is scheduled to be released in March 2025.
The workaround is to disable proxy-inline-ips and cp-acceleration.
Note: The inline IPS feature allows HTTP/HTTPS traffic to be processed directly in WAD for application control and IPS UTM features, reducing reliance on the IPS Engine.
config ips global
Logs required by FortiGate TAC for investigation:
get system status
execute tac report
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.