Skip to main content
l_fiorini
New Member
October 31, 2014
Question

Strange alert at strange time

  • October 31, 2014
  • 3 replies
  • 17454 views

Yesterday evening I got an strange alert from a Fortigate 50B I manage. Below there are some lines from the log.

What is strange is that at that time nobody ( I am ware of ) was accessing the Fortigate from http(192.168.5.6).

 

Any idea?

 

best regards,

LF

 

2014-10-30 21:19:01 log_id=0104032400 type=event subtype=admin pri=alert vd=root user="admin" ui=http(192.168.5.6) msg="Configuration is changed in the admin session" 2014-10-30 21:19:01 log_id=0104032003 type=event subtype=admin pri=information vd=root user="admin" ui=http(192.168.5.6) action=logout status=success reason=timeout msg="Administrator admin timed out on http(192.168.5.6)" 2014-10-30 21:18:59 log_id=0100020202 type=event subtype=system pri=information vd=root action=daemon-startup daemon=authd pid=811 msg="Daemon authd started" 2014-10-30 21:18:58 log_id=0100020203 type=event subtype=system pri=information vd=root action=daemon-shutdown daemon=authd pid=808 msg="Daemon authd shut down" 2014-10-30 21:18:57 log_id=0100020202 type=event subtype=system pri=information vd=root action=daemon-startup daemon=authd pid=808 msg="Daemon authd started" 2014-10-30 21:18:56 log_id=0104032301 type=event subtype=admin pri=notice vd=root user="daemon_admin" ui=init action=add-vdom msg="Virtual domain root is added" 2014-10-30 21:18:56 log_id=0100020203 type=event subtype=system pri=information vd=root action=daemon-shutdown daemon=authd pid=805 msg="Daemon authd shut down" 2014-10-30 21:18:18 log_id=0100020202 type=event subtype=system pri=information vd=root action=daemon-startup daemon=authd pid=805 msg="Daemon authd started" 2014-10-30 21:18:17 log_id=0100020203 type=event subtype=system pri=information vd=root action=daemon-shutdown daemon=authd pid=270 msg="Daemon authd shut down" 2014-10-30 21:18:09 log_id=0100020202 type=event subtype=system pri=information vd=root action=daemon-startup daemon=fdsmgmtd pid=802 msg="Daemon fdsmgmtd started" 2014-10-30 21:18:08 log_id=0100020203 type=event subtype=system pri=information vd=root action=daemon-shutdown daemon=fdsmgmtd pid=56 msg="Daemon fdsmgmtd shut down" 2014-10-30 21:18:08 log_id=0100020202 type=event subtype=system pri=information vd=root action=daemon-startup daemon=cmdbsvr pid=799 msg="Daemon cmdbsvr started" 2014-10-30 21:18:07 log_id=0100020203 type=event subtype=system pri=information vd=root action=daemon-shutdown daemon=cmdbsvr pid=22 msg="Daemon cmdbsvr shut down"

 

    3 replies

    Jeff_FTNT
    Staff
    Staff
    October 31, 2014

    FGT default enable "set revision-backup-on-logout enable " with CLI:config sys global /set revision-backup-on-logout enable /end

     

    So if Login  session change setting but did not back up to flash, when this admin session logout or timeout, FGT will automatically save revised  setting to flash, and you will see that event log  (logid=0100032400) for it.

    Dave_Hall
    New Member
    October 31, 2014

    I see this myself when I am working on some fgts -- forget to actually log out, but simply close browser window, session is still running.  (I have several other browser windows open as well.) 

     

    I was trying to figure out all the other "Daemon...shutdown/start up" events, but it dawn on me that the Fortigate would have to shutdown those daemons if it's going to back up the config.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!