Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Forti_Users
New Contributor

How often should I reboot a FortiGate?

Hi,

 

I have been asked the question as to whether there is any official documentation as to how often I should I reboot a Fortigate. I cant find anything.

If not what are the recommendations as to how often they should be restarted.

 

Thanks in advance. 

5 REPLIES 5
rwpatterson
Valued Contributor III

There really is no simple answer to that. Not wanting to sound like a wise ass, but the best answer would be 'when it starts to act strange'. Many factors may be involved in making that occur:

 * Over subscription of services

 * An underpowered device being driven hard

 * Extremely long uptime (2+ years)

 * Corrupted flash due to unexpected power loss (smaller models are susceptible)

 

There may be more, but off the top of my head, I can't think of them. Others will chime in, I'm sure.

 

Another reason that has nothing to do with acting strange would be the need to update the firmware.

 

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Bubu
Contributor

Hi,

No recommandations about that.

It's not necessary to reboot periodically the Fortigate, it manage itself the TTL for sessions, daemons...

It will reboot on upgrading, system settings changing and if the Fortigate has an undesired/forced shutdown/reboot, it's recommended to cleanly reboot it.

Bubu

Bubu
ede_pfau

@rwpatterson puts you into the picture. Best practice is that you proactively reboot the FGT while you can choose the right moment. Only after some TB have crossed a tiny desktop model or 2 years have gone without reboot you would start to notice some services failing. But, this will never happen...

...as you carefully keep your FGT up-to-date by patching! And this will happen at least 2-3 times per year.

 

@Bubu: I can't think of any config settings change that will force a reboot, except for creating or destroying a HA cluster, or changing the basic mode between NAT/Routing and Transparent. Both will likely only happen rarely.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Bubu

Ede_pfau,

Not for config settings but system settings, when the system settings changed, when the way of work of Fortigate change.

Bubu

Bubu
Dave_Hall
Honored Contributor

We manage about 40 smaller/mid-sized Fortigates in remote rural areas. and rarely need to reboot them for anything other than devices were reportedly "acting weird" or we can't log into the GUI.  Though, I think there was a time on the older 4.0 (mr3) firmware branches that some of smaller units (w/512 Mb) suffered more from memory leaks, that as a quick and dirty solution is to perform a scheduled nightly reboot.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors