Description | This article describes how to limit the max percentage of flow-based antivirus memory usage. |
Scope | FortiGate 7.4.2 or above. |
Solution |
Scenario: During busy hours, the increase in memory usage may caused by the large number of files that need to be scanned by the flow-based antivirus.
Behavior:
diagnose hardware sysinfo memory MemTotal: 8040256 kB Cached: XXXXXX kB ...... Shmem: YYYYYY kB
diagnose test application ipsmonitor 24 pid: 28619 from 20231013-15:17:26 to 20231013-16:13:13
Solution:
The maximum percentage of the system memory for a flow-based antivirus may be used for scanning.
config ips global set av-mem-limit Enter an integer value from <10> to <50> or (special = <0>). <----- <10> to <50> = 10% to 50%. 0 is default value and is used to disable this command. end
Flow-based antivirus will bypass the AV scan for currently buffering files.
config system global set av-failopen pass end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.