My current 100F firewall is configured with 400 sdwan spoke members and each member with a health check SLA, but when health-check set interval is set to 1500 ms it affect my CPU process and reach 100% is there any range or limit suggested to avoid CPU increase ?
Hi salassilvaj
1. Please help collect the logs when the CPU usage is high. Open several SSH sessions to gather the necessary information.
fnsysctl date
get sys perf status
diag sys top 1
diag sys mpstat 2 5
fnsysctl ps
2.1 Run the command: dia sys profile report
2.2 If the output of the command in 2.1 is 'Not profiling', please enable CPU profiling as per the guide below.
https://community.fortinet.com/t5/FortiGate/Technical-TiP-Debugs-for-troubleshooting-high-CPU-Issues...
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tips-FortiGate-CPU-Profiling/ta-p/274819
Run the CPU profiler, commands below:
diag sys profile cpumask <ID> <----- If all CPUs are busy, then do not need to run this. otherwise specifying busying CPU ID.
diag sys profile start
<wait 5-10 seconds>
diag sys profile stop
diag sys profile show order
diagnose sys profile show detail
diagnose sys profile sysmap
Please share the logs with me via my fortinet official email at bhoang@fortinet.com. I will investigate the issue or attempt to reproduce it in my lab. Many thanks
Bill
User | Count |
---|---|
2599 | |
1382 | |
803 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.