Skip to main content
csharma85
Staff
Staff
December 23, 2025

Troubleshooting Tip: Unable to generate TAC report past 'diagnose ips anomaly list'

  • December 23, 2025
  • 0 replies
  • 382 views
Description This article describes an issue where the 'diagnose ips anomaly list' command throws an error and closes the active SSH and Web CLI Session while generating a TAC report.
Scope FortiGate
Solution

With DOS firewall policies configured in FortiGate, using 'execute tac report' may result in the active SSH and Web CLI Session disconnecting upon reaching the command 'diagnose ips anomaly list'.

 

Additionally, running the command 'diagnose ips anomaly list' alone closes the connection.

 

Lab-FGT (root) # diagnose ips anomaly list
list nids meter:
total # of nids meters: 0.
free(): invalid pointer
Connection to 10.3.1.190 closed.

 

Use a workaround: Try running the 'diagnose ips anomaly list' command only in the VDOM where the DoS-policy is configured. 

 

To change VDOM settings, from the top level (global) following CLI command can be used to enter to any specific VDOM:

 

config vdom

edit <vdom_name> 

 

Each configured VDOM can also be accessed from the GUI. The following article describes the steps to access any specific VDOM configured on FortiGate: Technical Tip: How to search and get into the VDOM from FortiGate GUI.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.