Skip to main content
Best answer by SMabille

You can get a FAZ license for $1 on AWS for 500Gb and up to 2 "home" Fortigate/VDOM (up to Fortigate 90 and VM-01), still have to pay for AWS usage, I'm at around $25 a month.

(https://aws.amazon.com/marketplace/pp/B06Y1K63ZH?qid=1548667167351&sr=0-1&ref_=srh_res_product_title#pdp-overview)

 

dfollis wrote:

I have a home setup of the following:

 

FWF-60E v6.0.4 build0231 (6.0.4)

FSW-108D-POE v3.6.9-build0426 (this model does not support v6)

FortiAP FP221C v6.0-build0027 (just upgraded to build0030, 6.0.4)

 

Fairly simple setup for home using these devices.  I've experienced random outages after ~24 hours after upgrading from 6.0.3 to 6.0.4.  Symptom is Wifi will be down and hard wire connection to FWF-60E will not respond without a hard power reset.

 

I first tried to update my FSW from 3.6.8 to .9 but crash occurred again.  This AM after another hard reset was needed, I noticed that 6.0.4 for FP221C was released on 1/25 so I have just updated that.  As this is a home setup, I'm not paying for FAZ  (considering we spend thousands of dollars on FTNT gear at work sure would be nice for free FAZ with low daily limit for home use/testing, just saying :-)).

 

I do have a synology though so I'm going to enable SYSLOG and dump to that to see if I can get better system events.  When I check events logged to FortiCloud I don't see anything odd.  Running "diag debug crashlog read" shows the following:

 

1: 2019-01-26 22:27:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 2: 2019-01-26 22:27:12 <00152> scanunit=manager str="Success loading anti-virus database." 3: 2019-01-26 22:37:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 4: 2019-01-26 22:37:12 <00152> scanunit=manager str="Success loading anti-virus database." 5: 2019-01-26 22:40:14 the killed daemon is /bin/pyfcgid: status=0x0 6: 2019-01-26 22:59:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 7: 2019-01-26 22:59:12 <00152> scanunit=manager str="Success loading anti-virus database."

8: 2019-01-27 12:33:03 <00152> scanunit=manager str="Success loading anti-virus database."

 

It is interesting that that last event logged is an AV update until I reset it 12 hours later, see events 7 and 8 above.

 

Not sure if anyone else is seeing stability issues like this.  It is possible I have an odd config that is causing an issue as I have a few VLANs that are trunked over my FSW, but nothing unconventional that I'm aware of.  Will update post if I see another crash.

5 replies

GusTech
New Member
January 11, 2019

Nice!

 

522576 GUI always loading VPN interface when there is over 5k VPN tunnel interfaces.

What a bug.. Who have over 5k VPN tunnel interfaces?

 

 

mike_dp
New Member
January 11, 2019

Anyone tried it yet? We plan to try it in the next few days. Lots of bug fixes for sure!

GusTech
New Member
January 11, 2019

Tested 2*100e in lab, will test in production next week.

Jeroen_Nieuwenbroek
New Member
January 16, 2019

I got a lot of complaints about slower computers (response time between switching programs, opening websites)  since 6.0.4 was installed.

We use Windows 7 Proffesional and and use forticlient in combination with EMS

Every time when one of my colleages submits a helpdesk request i quickly login to the computer to look what is causing the slowdown of the computer. What i noticed is that fmon.exe generates a lot of hard faults. I disabled the vulnerability scan, planned scans, heuristics, and VPN with almost no effect. I even disabled searchindexer because while it was indexing the harddisk fmon was creating hard faults too.

 

Still my colleages notice sometimes delays.

 

We don't have this problems with our terminal servers Windows 2008R2 running with 6.0.4

 

mracpa
Explorer
January 16, 2019

Just upgraded from 6.0.3 to 6.0.4 last night.  No issues noted yet.  The GUI seems to have been tweaked for better visibility.  Improved font size maybe?  Pages also load MUCH faster than in 6.0.3.

ricardoduarte
New Member
January 16, 2019

After 6.0.4, my 200E no longer updates from Fortiguard or manually.

It gives an error all the time.

Downgraded to 5.6.7 and it works.

goroga
New Member
January 18, 2019

One issue in this version:

On FortiGate 101E "Log & reports > Forward Traffic" filters are ineffective. 

PeterK
Visitor III
January 23, 2019

Anyone else notice that sequence numbers have disappeared.  We have hundreds of policies on some of our interfaces.  This makes it difficult to know if one policy is above another without slowly scrolling through every policy.  Not sure if this has been removed deliberately.

tgold
New Member
January 24, 2019

Does anyone know when Forticloud will support 6.0.4 for management? It currently won't allow me to enable management.

seadave
New Member
January 27, 2019

I have a home setup of the following:

 

FWF-60E v6.0.4 build0231 (6.0.4)

FSW-108D-POE v3.6.9-build0426 (this model does not support v6)

FortiAP FP221C v6.0-build0027 (just upgraded to build0030, 6.0.4)

 

Fairly simple setup for home using these devices.  I've experienced random outages after ~24 hours after upgrading from 6.0.3 to 6.0.4.  Symptom is Wifi will be down and hard wire connection to FWF-60E will not respond without a hard power reset.

 

I first tried to update my FSW from 3.6.8 to .9 but crash occurred again.  This AM after another hard reset was needed, I noticed that 6.0.4 for FP221C was released on 1/25 so I have just updated that.  As this is a home setup, I'm not paying for FAZ  (considering we spend thousands of dollars on FTNT gear at work sure would be nice for free FAZ with low daily limit for home use/testing, just saying :-)).

 

I do have a synology though so I'm going to enable SYSLOG and dump to that to see if I can get better system events.  When I check events logged to FortiCloud I don't see anything odd.  Running "diag debug crashlog read" shows the following:

 

1: 2019-01-26 22:27:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 2: 2019-01-26 22:27:12 <00152> scanunit=manager str="Success loading anti-virus database." 3: 2019-01-26 22:37:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 4: 2019-01-26 22:37:12 <00152> scanunit=manager str="Success loading anti-virus database." 5: 2019-01-26 22:40:14 the killed daemon is /bin/pyfcgid: status=0x0 6: 2019-01-26 22:59:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 7: 2019-01-26 22:59:12 <00152> scanunit=manager str="Success loading anti-virus database."

8: 2019-01-27 12:33:03 <00152> scanunit=manager str="Success loading anti-virus database."

 

It is interesting that that last event logged is an AV update until I reset it 12 hours later, see events 7 and 8 above.

 

Not sure if anyone else is seeing stability issues like this.  It is possible I have an odd config that is causing an issue as I have a few VLANs that are trunked over my FSW, but nothing unconventional that I'm aware of.  Will update post if I see another crash.

SMabille
SMabilleAnswer
New Member
January 28, 2019

You can get a FAZ license for $1 on AWS for 500Gb and up to 2 "home" Fortigate/VDOM (up to Fortigate 90 and VM-01), still have to pay for AWS usage, I'm at around $25 a month.

(https://aws.amazon.com/marketplace/pp/B06Y1K63ZH?qid=1548667167351&sr=0-1&ref_=srh_res_product_title#pdp-overview)

 

dfollis wrote:

I have a home setup of the following:

 

FWF-60E v6.0.4 build0231 (6.0.4)

FSW-108D-POE v3.6.9-build0426 (this model does not support v6)

FortiAP FP221C v6.0-build0027 (just upgraded to build0030, 6.0.4)

 

Fairly simple setup for home using these devices.  I've experienced random outages after ~24 hours after upgrading from 6.0.3 to 6.0.4.  Symptom is Wifi will be down and hard wire connection to FWF-60E will not respond without a hard power reset.

 

I first tried to update my FSW from 3.6.8 to .9 but crash occurred again.  This AM after another hard reset was needed, I noticed that 6.0.4 for FP221C was released on 1/25 so I have just updated that.  As this is a home setup, I'm not paying for FAZ  (considering we spend thousands of dollars on FTNT gear at work sure would be nice for free FAZ with low daily limit for home use/testing, just saying :-)).

 

I do have a synology though so I'm going to enable SYSLOG and dump to that to see if I can get better system events.  When I check events logged to FortiCloud I don't see anything odd.  Running "diag debug crashlog read" shows the following:

 

1: 2019-01-26 22:27:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 2: 2019-01-26 22:27:12 <00152> scanunit=manager str="Success loading anti-virus database." 3: 2019-01-26 22:37:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 4: 2019-01-26 22:37:12 <00152> scanunit=manager str="Success loading anti-virus database." 5: 2019-01-26 22:40:14 the killed daemon is /bin/pyfcgid: status=0x0 6: 2019-01-26 22:59:10 scanunit=manager pid=152 str="AV database changed; restarting workers" 7: 2019-01-26 22:59:12 <00152> scanunit=manager str="Success loading anti-virus database."

8: 2019-01-27 12:33:03 <00152> scanunit=manager str="Success loading anti-virus database."

 

It is interesting that that last event logged is an AV update until I reset it 12 hours later, see events 7 and 8 above.

 

Not sure if anyone else is seeing stability issues like this.  It is possible I have an odd config that is causing an issue as I have a few VLANs that are trunked over my FSW, but nothing unconventional that I'm aware of.  Will update post if I see another crash.

seadave
New Member
January 29, 2019

@SMaBille you changed my life.  It is funny how you can be so advanced at somethings, and be aware of other solutions that you at the time do not use, until someone says "hey dummy, try this!"  I stood up a FAZ in AWS today.  My first AWS VM by the way, and it works great.  I went with the $1, t2.tiny instance, already had IAM configured for Glacier, created my ssh keys, applied a firewall policy, and I was able to sync my FWF-60E to it on the first try.  Awesome.  Amazon suggests it will cost $17/month which is fine by me considering what I paid previously for a FAZ VM license on my home network.  So now that it is running, I am seeing a ton of messages similar to what was reported above:

 

Destination IP127.0.0.1 Source IP127.0.0.1 Device IDFWF60E4Q1####### Device NameGATE Useradmin User Interfacehttps(127.0.0.1) Methodhttps Sub Typesystem Typeevent Actionlogin Levelalert Reasonpasswd_invalid Log DescriptionAdmin login failed Log ID0100032002 MessageAdministrator admin login failed from https(127.0.0.1) because of invalid password SN0 Statusfailed Virtual Domainroot Date/Time00:29:50 Destination End User ID0 Destination Endpoint ID3 Device Time2019-01-29 00:29:50 End User ID3 Endpoint ID3 Event Time1548750590 Time Stamp2019-01-29 00:29:50 bid1365 dvid1026 idseq205745199928836098 logver60

 

This makes no sense to me as I am not logging into a local host address?  I also do not have the HTML5 console open for extended periods.  This is repeated every 60 seconds, whether I am logged into the UI or not.

 

My FWF-60E has been crashing after ~12 hours it seems.  Hard reset brings it back.  Now that it is talking to FAZ I should be able to get better telemetry if it happens again.  Before I setup the FAZ I was logging to memory and a syslog device.  I have both of those options disabled now.  Will see if that helps.