Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cbialobz
New Contributor

Recommendation for most memory efficient FortiOS post 4.0 MR1 patch 10

Hello: Have a few 60Bs and 100a that go in and out of conserve mode. Currently at 4.0 MR1 patch 10. Ultimate fix is probably a HW upgrade at this point, but in the interim I may try upgrading the FortiOS, but I am somewhat hesitant as I don' t know if the newer version are better at memory utilization or worse. Any experiences or recommendations? Thanks in advance
3 REPLIES 3
Dave_Hall
Honored Contributor

Personally, if I had the choice and features wasn' t a factor I' d keep those low-end fgts on 4.0 MR2. (Otherwise, 4.0 MR3 all the way. :-) The thing I " hated" most about 4.0 MR1 is the constant high CPU and memory usage. I recall (and looking back now) right out of the box (a fresh exec factoryreset) you really needed to tweak the UTM/IPS/Protocol Options -- otherwise the fgt would literately scan/process every single packet for " known" protocols. Right on the front section (bottom right-corner) of the Fortinet KB is an KB on " conserve mode" , which provides some tips on dealing with conserve mode. But I think you' ll see a noticeable difference if only setting the protocol options to use actual port numbers (and not set to 0, which is auto.) My 2 cents.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

I' d say go for 4.2.15.
But I think you' ll see a noticeable difference if only setting the protocol options to use actual port numbers (and not set to 0, which is auto.)
Yes and no. You should be aware that the FGT can scan some protocols INDEPENDENT of their well known ports, for example ftp or http. This is a big advantage on the security side whereas it costs on the CPU side. There' s nothing like a free lunch.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
rwpatterson
Valued Contributor III

none of my smaller boxes are ever hammered, but I found issues with 4.1.10 that made me glad to get away from it. Having two 1000As doing my heavy lifting, memory and CPU were never an issue, but even on those large boxes 4.1.10 gave me grief. Switching to 4.2.x was uneventful, and help me sleep better. If you are going to do the upgrades, 2 things I would recommend: 1) Reboot the units prior to uploading the new code. 2) check out my post here: https://forum.fortinet.com/FindPost/81337

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors