Description |
This article describes how to detect the potential network loop, which causes high CPU usage in the FortiGate firewall. |
Scope | FortiGate before v7.6.0. |
Solution |
Seeing a high CPU because of softirq may be a sign of a potential network loop, especially in a FortiGate that has Transparent mode OR a switch-interface.
For example, this is the output from the command 'diagnose sys mpstat'.
diagnose netlink brctl list
diagnose netlink brctl name host [name]
This will make it possible to check if any MAC address appears in different interfaces. In such cases, it is recommended to review the network design. By right, a MAC address should appear and stick to only 1 interface.
Related documents: FortiOS 7.6.0 release notes - new features. Logging MAC address flapping events Troubleshooting Tip: Check SoftIrq increments (recommended when experiencing high CPU usage) Technical Tip: Software switch causing high CPU softirq usage and network downtime |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.