FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ChrisTan
Staff
Staff
Article Id 426465
Description This article describes an issue with the logical serial number feature in HA that leads FortiGate to enter conserve mode.
Scope FortiGate v7.4.9.
Solution

Logical SN is enabled under HA config:

 

config system ha
...
    set logical-sn enable
...
end

 

This feature enables two FortiGate serial numbers to be associated with each other on FortiCare to create a single virtual serial number (vSN). It allows FortiGate HA to share a single order of the following subscriptions:

  • Enterprise Protection.

  • Unified Threat Protection (UTP).

  • Advanced Threat Protection (ATP).

 

When logical-sn is enabled, the urlfilter uses the logical-sn certificate for TLS connections.

It could cause the urlfilter daemon memory leak every time the client certificate was requested.

 

diagnose sys top-all 1 100 1


0U, 0N, 0S, 100I, 0WA, 0HI, 0SI, 0ST; 3717T, 372F
lnkmtd 236 S 1.9 0.7 2
urlfilter 360 S < 0.0 32.0 0   <-----------------
node 209 S 0.0 7.1 3
ipsengine 401 S < 0.0 3.2 7

 

This issue will be fixed in the future version.