Skip to main content
ntluan56
Explorer II
February 2, 2023
Solved

fortigate slave disk error can make master high cpu ?

  • February 2, 2023
  • 1 reply
  • 2413 views

Hello everyone,

We are facing a weird situation.

With 1500D HA cluster (active-pasive),  yesterday slave had below messages:

     XT2-fs (sda3): previous I/O error to superblock detected
     Cannot open /daEXT2-fs (sda3): previous I/O error to superblock detected
     ta2/geodb/geoip.EXT2-fs (sda3): previous I/O error to superblock detected
     4. Error=Input/oEXT2-fs (sda3): previous I/O error to superblock detected

     ....

 

Some services were afftected.

  • Can't see any log when access to slave from GUI
  • Can't get snmp data from mgmt port of master sometimes, seem like high cpu happened.
  • IPsec multiple sites are not connected (Ping, remote desktop, file sharing, etc.) However, SSL-VPN can be connected and operated
  • After we shutdown slave, everything went ok

I am wondering, a disk/partion failed on slave can affect master performance. 

Is there any information about this case ? 

 

Thank you. 

 

Best answer by gfleming

Sorry what's your concern about not having basic log monitoring? What are you looking for exactly?

 

This might be relevant? https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/313152/out-of-band-management-with-reserved-management-interfaces

 

Also what's more concerning about running 6.2 is the fact that it's been EOES for almost a year and goes EOS in about half a year. You should look at upgrading pretty soon...

1 reply

gfleming
Staff
Staff
February 2, 2023

This sounds like something you should be talking to TAC about to be honest.

ntluan56
ntluan56Author
Explorer II
February 3, 2023

We have replaced the slave and also rebuilt the HA cluster. Everything is fine.

The fact that our system is still running on 6.2.x firmware and doesn't even have basic log monitoring is concerning.

It's necessary to monitor logs in real-time and take immediate action, even on the slave side.

Thank you!

gfleming
Staff
gflemingAnswer
Staff
February 3, 2023

Sorry what's your concern about not having basic log monitoring? What are you looking for exactly?

 

This might be relevant? https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/313152/out-of-band-management-with-reserved-management-interfaces

 

Also what's more concerning about running 6.2 is the fact that it's been EOES for almost a year and goes EOS in about half a year. You should look at upgrading pretty soon...