FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
csharma85
Staff
Staff
Article Id 422562
Description This article describes an issue where the 'diagnose ips anomaly list' command throws an error and closes the active SSH and Web CLI Session while generating a TAC report.
Scope FortiGate
Solution

With DOS firewall policies configured in FortiGate, using 'execute tac report' may result in the active SSH and Web CLI Session disconnecting upon reaching the command 'diagnose ips anomaly list'.

 

Additionally, running the command 'diagnose ips anomaly list' alone closes the connection.

 

Lab-FGT (root) # diagnose ips anomaly list
list nids meter:
total # of nids meters: 0.
free(): invalid pointer
Connection to 10.3.1.190 closed.

 

Use a workaround: Try running the 'diagnose ips anomaly list' command only in the VDOM where the DoS-policy is configured. 

 

To change VDOM settings, from the top level (global) following CLI command can be used to enter to any specific VDOM:

 

config vdom

edit <vdom_name> 

 

Each configured VDOM can also be accessed from the GUI. The following article describes the steps to access any specific VDOM configured on FortiGate: Technical Tip: How to search and get into the VDOM from FortiGate GUI.