hi,
i'll be creating multiple (a lot) SNAT policy in a multi-VDOM FGT which is an "F" series (1000 plus model)
my question, do i enable/allow log "all sessions" or just "security events"?
can my current platform (1000 plus F model) can handle such log?
i just want to prevent any high CPU/memory due to lots of NAT processing/cache.
Solved! Go to Solution.
Hi @johnlloyd_13 ,
Technically, it's hard to cause high CPU/Memory usage issues due to NAT usage.
1) The following doc is talking about possible reasons causing high CPU:
2) The KB is talking about something for conserve mode (Memory usage issue)
hi,
thanks for these links! appreciate it.
i just want to make sure it's "safe" in our FGT devices since i know our platform is "bigger" or more "beefy" model.
Hi @johnlloyd_13 ,
It all depends on your configuration, traffic throughput, system resources, and so on.
For example, if your protected network is for only 10-20 users, I would say, FGT 1000F is safe enough for you. But if all of the users are using something exhausting the system resources, such as always downloading/uploading large files/videos, large server DBs replica activities through this FGT every day, and no external log storage methods (log enabled in all firewall policies so all logs are memory based), and so on. Eventually, your FGT will have a big chance to be experiencing high CPU / Memory usage issues.
User | Count |
---|---|
2270 | |
1232 | |
772 | |
452 | |
396 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.