Skip to main content

CPU is pinned

(2018-06-11)

Problem

CPU on Fortigate is maxed out for a long period of time (hours, days).

Solution

Identify the process using the CPU:

get system performance top

It should be obvious which process is using all the CPU. Note the PID of the offending process.

If it is sslvpn, it is reasonably safe to restart (although connected clients may get kicked off -- so List SSLVPN Users first!):

diag sys kill 11 $PID

If it isn't sslvpn, it may be safer to reboot the firewall.

Commentary

This problem is not uncommon on 5.4.x, especially 5.4.6.