Skip to main content
Alby23
New Member
September 14, 2016
Question

Pieces of configuration purged... what is the source...?

  • September 14, 2016
  • 1 reply
  • 23902 views

I'm a little bit confused.

In a FortiOS 5.4.0 appliance I've suddendly lost firewall policies and routing and in event logs I see these entries (attached image).

 

Same second... 4 commands. Any ideas???

    1 reply

    pyy
    New Member
    September 23, 2016

    Purge means that someone delete all the section config

     

    ex

    config firewall policy

    edit x

    next .

    .

    .

    edit y

    next

     

    edit 10

    mpla mpla

    next

    purge

     

    purge will delete x,y,10

     

    So the admin add a static route/fw policy and  instead of use delete in order to delete the entry he use the purge and delete all the section

     

     

    ede_pfau
    SuperUser
    SuperUser
    September 24, 2016

    Probably an upgrade gone wrong. Upgrades do not only comprise firmware code but transformation procedures as well. Somehow these went wild, that's where the 'purge' commands come in.

     

    The routes and OSPF config etc. is just the last part of a config file. The FGT will boot with a partial config file just fine, surprisingly.

     

    I'd rebuild the flash disk from scratch via the boot manager (connect via serial port, stop the boot process, reformat the disk, reload firmware via TFTP, reload the config).

    emnoc
    New Member
    September 24, 2016

    I would use the cfg revision to see 'exactly' what was b4 and after. The log seems to show this was a "admin" event, so if that is true at least the log systems will have the address of the user.