Skip to main content
andrewbailey
New Member
July 12, 2017
Question

5.6 on FGT-60E- SMNPD Crashes

  • July 12, 2017
  • 8 replies
  • 8887 views

Hi folks,

 

I have a new Fortigate 60E running. It's using configuration from an FGT-80D translated via FortiConveter (not sure if this is or isn't relevant yet). Both devices are running 5.6 GA Build 1449.

 

I'm seeing system events like this:-

 

 [size="2"]Pid: 04450, application: snmpd, Firmware: FortiGate-60E v5.6.0,build1449b1449,170330 (GA) (Release), Signal 11 received, Backtrace: [0x00ce37ba] [0x56dcabf0][/size]

 

These were not being seen on the FGT-80D.The SNMPD (which this crash seems to refer to) appears to be disabled:-

 

routerXXXX # config system snmp sysinfo

 

routerXXXX (sysinfo) # get

status : disable

engine-id :

description :

contact-info :

location :

trap-high-cpu-threshold: 80

trap-low-memory-threshold: 80

trap-log-full-threshold: 90

Does anyone have any thoughts or ideas? Perhaps this one might be worth a ticket? Kind Regards, Andy.

8 replies

andreotta
New Member
July 12, 2017

Hey Andy,

Could you paste a  show system interfaces ?

 

Regards

Andre

andrewbailey
New Member
July 12, 2017

Andre,

 

Yes, I'll include that below.

 

I must admit- that was one of my first checks too. I noticed that in the original config there was some repeated SNMP indexes (ie some interfaces using the same SNMP index).

 

I "unset snmp-index" on all interfaces and that seems to have cleared that issue, but the errors are still occuring. As they stand the snmp-indexes aren't very "logical" but I guess that shouldn't be too important as long as they are unique.

 

Here's the config for the interfaces anyway (with a few XXX's to replace any sensitive bits):-

 

router (interface) # show config system interface     edit "wan1"         set vdom "root"         set ip 0.0.0.0 255.255.255.255         set vlanforward enable         set ident-accept enable         set type physical         set scan-botnet-connections block         set description "Connection to XXX ISP"         set alias "WAN"         set estimated-upstream-bandwidth 19000         set estimated-downstream-bandwidth 74000         set role wan         set snmp-index 4     next     edit "wan2"         set vdom "root"         set mode dhcp         set allowaccess ping         set type physical         set role wan         set snmp-index 11     next     edit "dmz"         set vdom "root"         set ip 10.10.XXX.1 255.255.255.0         set type physical         set role dmz         set snmp-index 3     next     edit "internal1"         set vdom "root"         set ip 192.168.XX.1 255.255.255.0         set allowaccess ping https ssh         set vlanforward enable         set type physical         set scan-botnet-connections block         set alias "LAN1"         set device-identification enable         set lldp-transmission enable         set fortiheartbeat enable         set role lan         set snmp-index 1         config ipv6             set ip6-allowaccess ping https ssh             set ip6-address 2001:XXX:ba02:ed3f::100:1/120             set ip6-send-adv enable             set ip6-manage-flag enable             set ip6-other-flag enable             config ip6-prefix-list                 edit 2001:XXX:ba02:ed3f::100:0/120                     set autonomous-flag enable                     set onlink-flag enable                     set valid-life-time 7200                     set preferred-life-time 7200                 next             end         end     next     edit "internal2"         set vdom "root"         set ip 192.168.XX.1 255.255.255.0         set vlanforward enable         set type physical         set scan-botnet-connections block         set alias "LAN2"         set device-identification enable         set lldp-transmission enable         set fortiheartbeat enable         set role lan         set snmp-index 2         config ipv6             set ip6-address 2001:XXX:ba02:ed3f::200:1/120             set ip6-send-adv enable             set ip6-manage-flag enable             set ip6-other-flag enable             config ip6-prefix-list                 edit 2001:XXX:ba02:ed3f::200:1/128                     set autonomous-flag enable                     set onlink-flag enable                     set valid-life-time 3600                     set preferred-life-time 3600                 next             end         end     next     edit "internal3"         set vdom "root"         set type physical         set snmp-index 12     next     edit "internal4"         set vdom "root"         set type physical         set snmp-index 10     next     edit "modem"         set vdom "root"         set mode pppoe         set vlanforward enable         set type physical         set snmp-index 5         set lcp-echo-interval 1     next     edit "ssl.root"         set vdom "root"         set type tunnel         set alias "SSL VPN interface"         set snmp-index 6     next     edit "internal"         set vdom "root"         set ip 192.168.XX.99 255.255.255.0         set allowaccess ping https ssh         set type hard-switch         set stp enable         set role lan         set snmp-index 8     next     edit "WANIPv6"         set vdom "root"         set mode pppoe         set distance 10         set allowaccess ping         set type tunnel         set scan-botnet-connections block         set estimated-upstream-bandwidth 19000         set estimated-downstream-bandwidth 74000         set role wan         set snmp-index 7         config ipv6             set ip6-mode dhcp             set ip6-allowaccess ping             set dhcp6-prefix-delegation enable         end         set dns-server-override disable         set interface "wan1"     next     edit "iOS VPN"         set vdom "root"         set type tunnel         set snmp-index 9         set interface "WANIPv6"     next end

I also noticed the events are quite "bursty". After I had refreshed the SNMP indexes I had 8 within an hour (nearly two hours ago) and then nothing since. Each time the error occured the PID associated with the event increased which makes me wonder if I might ultimately hit some limit and see the Fortigate crash completely? Not sure how that side of things works.

 

Any other thoughts?

 

Kind Regards,

 

 

Andy.

andreotta
New Member
July 13, 2017

Hey Andy,

 

Yeah I really intended to check the snmp indexes, because I already had a problem with the same index in both interfaces. But you're already checked that.

I don't think about crash completely. The PID is only because with the signal 11 the process restart and each time with a new PID. I think this is a kind of bug, because nothing related to indexes or snmp config. More later I'll check here in my lab using 5.6.

 

 

Regards, Andre

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.