Description |
This article describes the situation where the av-mem-limit feature doesn’t work properly when setting “av-failopen pass” in FortiGate v7.4.4. |
Scope |
FortiGate v7.4.4 |
Solution |
config ips global set av-mem-limit xx end
xx is an integer value from <10> to <50>.
config system global set av-failopen pass end
To fix:
Configure av-failopen to be 'off' or 'one-shot'.
config system global set av-failopen yy end
yy is off or one-shot.
It is necessary to upgrade FortiGate firmware version to be v7.4.6, v7.6.1, or above. |