Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
salassilvaj
New Contributor III

sdwan config health check over cpu process

My current 100F firewall is configured with 400 sdwan spoke members and each member with a health check SLA, but when health-check set interval is set to 1500 ms it affect my CPU process and reach 100% is there any range or limit suggested to avoid CPU increase ?

 

Jonathan Salas
Jonathan Salas
1 REPLY 1
BillH_FTNT
Staff
Staff

Hi salassilvaj

 

1. Please help collect the logs when the CPU usage is high. Open several SSH sessions to gather the necessary information.

fnsysctl date
get sys perf status
diag sys top 1
diag sys mpstat 2 5
fnsysctl ps

 

2.1 Run the command: dia sys profile report

2.2 If the output of the command in 2.1 is 'Not profiling', please enable CPU profiling as per the guide below.

 

https://community.fortinet.com/t5/FortiGate/Technical-TiP-Debugs-for-troubleshooting-high-CPU-Issues...
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tips-FortiGate-CPU-Profiling/ta-p/274819

 

Run the CPU profiler, commands below:
diag sys profile cpumask <ID> <----- If all CPUs are busy, then do not need to run this. otherwise specifying busying CPU ID.
diag sys profile start
<wait 5-10 seconds>
diag sys profile stop
diag sys profile show order
diagnose sys profile show detail
diagnose sys profile sysmap

 

Please share the logs with me via my fortinet official email at bhoang@fortinet.com. I will investigate the issue or attempt to reproduce it in my lab. Many thanks

Bill

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors