Skip to main content
ssanga
Staff & Editor
Staff & Editor
October 14, 2024

Technical Tip: FortiGate-100E/101E becomes unresponsive (No GUI,SSH, console) and requires reboot to regain access

  • October 14, 2024
  • 0 replies
  • 443 views
Description This article provides a solution to resolve an issue where the FortiGate 100 series may become unresponsive without any access(GUI, SSH, console) requiring a reboot to regain access due to an issue with the SOC3.
Scope FortiGate-100 series models running v7.0.11, v7.0.12, v7.0.13, v7.0.14, v7.0.15.
Solution

Under very rare timing conditions, data corruption may occur in a dirty cache line, potentially causing the device to become unresponsive to administrative access.
Pings to the FortiGate interfaces may be successful but the access for administrative purposes will not be available at the time of issue.

The issue has been resolved in v7.0.16, v7.2.11, v7.4.5, v7.6.1.  

 

To troubleshoot similar issues on FortiGate-100E/101E, capture the following data via the console connection to the FortiGate after the device reboots, and run a monitoring script while working with Fortinet Support.

  1. Connect the console to the affected FortiGates and log all output.
  2. Keep the console connection and log any errors displayed on the console session into a file until the issue reoccurs.
  3. Run the following commands multiple times on some affected FortiGates using a monitoring script.

 

fnsysctl date
get sys perf status
get sys status
get sys ha status
diag sys session stat
dia sys session full

dia har sys slab
dia har sys mem
dia har sys inter

diag cp soc3 vpn-stats 0
diag cp soc3 ssl-stats
diag cp soc3 pkce-stats 0
diag npu np6lite dce
diag npu np6lite anomaly-drop
diag npu np6lite session-stats

dia vpn tun list
diag vpn ipsec status
diag snmp ip frags
diag vpn ike gateway list
diag autoupdate versions