Skip to main content
jtfinley
New Member
October 30, 2010
Question

Random reboots

  • October 30, 2010
  • 20 replies
  • 9946 views
My Fortigate WIFI 60B, latest build (v4.0,build0291,100824 (MR2 Patch 2)) is randomly rebooting. I can' t see a cause for it other than this little blurb in the Event Log. 317 2010-10-30 17:49:00 information dhcp 26001 Client requests IP address/configuration parameters 318 2010-10-30 17:49:00 information system 20001 authentication Client 00:23:12:0b:2d:6b does WPA 319 2010-10-30 17:49:00 information system 20001 associate Accepted association from 00:23:12:0b:2d:6b 320 2010-10-30 17:48:55 information admin 32006 Fortigate started 321 2010-10-30 17:48:55 notice admin 32401 init add Administrator daemon_admin added an application control list WoW-Choke from init 322 2010-10-30 17:48:55 notice admin 32401 init add Administrator daemon_admin added an application control list monitor-p2p-and-media from init 323 2010-10-30 17:48:55 notice admin 32401 init add Administrator daemon_admin added an application control list block-p2p from init 324 2010-10-30 17:48:55 notice admin 32401 init add Administrator daemon_admin added an application control list monitor-all from init 325 2010-10-30 17:48:55 notice admin 32120 init add Administrator daemon_admin added an address all from init

    20 replies

    jmac
    New Member
    October 31, 2010
    No help, but a possible trend. I support a FortiGate-60B running 4.2.2 which after upgrading to that release started randomly restarting once every 2 to 10 days. Fortinet RMA' d the unit and I have just determined the replacement is doing the same. Seems like something in the 4.2.2 firmware may be at fault. I' m hesitant to go back to 4.2.1 as there were essential bug fixes in 4.2.2 which were needed for that site, and the 4.2 general release solved a different issue. Examining the logs prior to the restart do not indicate anything abnormal. The unit has a UTM bundle subscription and uses AV, IPS, and Application Control services. Users are authenticated via FSAE (latest version). The restart time-of-day and duration between restarts does not reflect a pattern and doesn' t point to any obvious contributing factors. I have a FortiWiFi-60B in my office running 4.2.2 which has not experienced the problem. The primary difference for my office unit is it has much lower traffic volume and the service subscription expired recently so it is no longer receiving AV/IPS updates. To see if the update process might be contributing to the issue, I have now made a change on the restarting unit to disable push updates and set scheduled updates to once a day at a set time I can use for comparison.
    jtfinley
    jtfinleyAuthor
    New Member
    October 31, 2010
    Interesting. I once experienced (2) reboots in a 10 minute period, but can go for a few days. I work wireless, so out of no where, I' ll see my wireless signal drop and DHCP query. I' ll get reports the Internet is down until it boots. I don' t see anything abnormal similar to your findings. I have it update AV signatures every hour.
    ede_pfau
    SuperUser
    SuperUser
    November 1, 2010
    Crashes indicate either a software bug (zero pointer reference) or a 100% memory consumption. This can be caused by a faulty process, a memory leak etc. I' d try to switch off the mentioned malware features to see if it influences the interval between crashes. If you find anything that can be replicated, open a support call with Fortinet. They' ll fix it but only if it is reasonably easy and reliably to reproduce. Years ago my 50A started to reboot all of a sudden, and only stopped when I disconnected the WAN line. Some evil network had hammered away at the poor box so violently that it couldn' t keep up with the traffic and crashed onto the wall. But from your description I don' t think you have a similar case here.
    jmac
    New Member
    November 1, 2010
    The FG-60B I have had problems with I monitor through SNMP and collect CPU, memory, session count and bandwidth data. I have not seen any indication of memory issues or traffic changes before it restarts. A cold start trap tells me when it restarts. I also collect full logs via syslog, including traffic, webfilter and app-control. Nothing stands out prior to the time of the restart as different or unusual compared to any other time. As of now, it' s been running for 2 days 3 hours since the start restart. I' m waiting to see if scheduled update timing makes a difference or not. I had a ticket open when the original unit was RMA' d but I' m not going to re-open it without some additional evidence or it will probably be a waste of time. Other than that, I can only hope it may go away when 4.2.3 or 4.3.0 is released.
    ede_pfau
    SuperUser
    SuperUser
    November 2, 2010
    could it be power surges/spikes? Do you have a spare UPS to try it out?
    Contributor III
    November 3, 2010
    I support a client with with a single 60B at each of their two sites. I recently upgraded to both units 4.2.2 build 291 and have seen random reboots since the upgrade on both devices. I also have SNMP monitoring on both devices and neither device shows any kind of spike prior to the reboots nor are there entries in the logs that indicate a problem. Has anyone had any luck in determining how to prevent 60B' s with 4.2.2 from randomly rebooting. This client is very sensitive to downtime, so even a 5 minute reboot in the middle of the day is a problem. We are looking to upgrade to a High Availability setup, but it would be nice to stabilize current setup in the mean time.
    jtfinley
    jtfinleyAuthor
    New Member
    November 3, 2010
    dsant1, No I have not resolved it yet. However, we have not had a reboot in 2 days. It must be something with IPS,AV or something. Perhaps you can open a case w/ Fortinet since you have logs. I' m not syslogging but I probably should setup a box to do so.
    ede_pfau
    SuperUser
    SuperUser
    November 4, 2010
    @dsant1: I recommend downgrading to 4.1.8. Normally, downgrading will wipe out the configuration but I have done it before without any troubles like that. Be sure to have a recent config backup before you start. You can downgrade one side after the other, the version does not influence VPN or routing. And then open a support case with Fortinet to learn if anybody else has already reported this and maybe a bugfix is available.
    jtfinley
    jtfinleyAuthor
    New Member
    November 11, 2010
    I opened a ticket on this #466960. It' s happening way too often. I' m having issues w/ my Fortimanager also using build v4.0-build0374 101008 (MR2 Patch 3). Joe
    jtfinley
    jtfinleyAuthor
    New Member
    November 15, 2010
    Well, here is Fortinet' s reply to my ticket. Hello Joseph, Your issue may be part of a bug that we are currently working on. Going back to the older firmware should fix the issue. You can then upgrade again to 4.0 MR2 Patch2 or wait for a new release. Thank you, Hassan Harb Fortinet TAC Americas 1-866-648-4638 https://support.fortinet.com
    Coldfirex
    New Member
    November 22, 2010
    We have been seeing this on our FWF60B as well the last couple of weeks. We are also at v4 MR2 P2. Did they give any indication on when the fix would be released?
    jtfinley
    jtfinleyAuthor
    New Member
    November 22, 2010
    Coldfirex - No, they have not indicated. I would recommend down one patch level.
    Coldfirex
    New Member
    November 23, 2010
    Thanks jtfinley. Unfortunately downgrading makes me pretty nervous. Would scheduling a reboot in the middle of the night, daily, get around this for the time being? If so, how could that be accomplished?
    jtfinley
    jtfinleyAuthor
    New Member
    November 23, 2010
    Thanks jtfinley. Unfortunately downgrading makes me pretty nervous. Would scheduling a reboot in the middle of the night, daily, get around this for the time being? If so, how could that be accomplished?
    I downgraded just fine. It only becomes a major issue if you downgrade a complete REVISION. All my settings were maintained after downgrading to the lesser Patch Level (1).
    Coldfirex
    New Member
    December 9, 2010
    jtfinley: I plan to attempt the downgrade. Has it been working well for you since? We are seeing a random reboot almost everyday currently. Is the downgrade process the same as upgrading where you simply upload the firmware version and apply it?
    ede_pfau
    SuperUser
    SuperUser
    December 9, 2010
    Yes, it is. Depending on the FG model you could load the older revision into the backup location on flash and reboot at a specified time. conf sys global set daily-restart enable set restart 00:00 ... You' ll have to look up the details in the CLI Guide and Admin Reference. Don' t forget to disable daily-restart the next morning :)
    jtfinley
    jtfinleyAuthor
    New Member
    January 14, 2011
    ede_pfau, Thank you for that info! I use this for a specific customer. Was unaware of a daily reboot. A certain cable provider we have will just stop talking to our Fortigate - a daily reboot resolves it. Work-around yes, but has not had an issue since.
    Coldfirex
    New Member
    January 1, 2011
    Im supposing this is probably still an issue in v4 MR2 P3?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!