Hi all
Have been experiencing a strange issue on 600F firewalls in HA running version 7.2.11 it just stop responsive and like frozen but all interfaces will be up but not pingable internet links down all interfaces not pingable unresponsive.. and the only way to fix the issue it to reboot the Primary FW, Its doesn't failover guess coz HA heartbeat and monitored interfaces will be still showing up... This has happened 3 times for the past 3 months like every after 25-35 days.
Any suggestions or anyone experienced same issue ?
Hi Lwazi
We need additional logs and configuration details to help identify the issue. If you're okay with it, please share them with me via my official email: bhoang@fortinet.com. I’m Bill from Fortinet.
Please provide the following:
1.System/Event logs – preferably in syslog or FortiAnalyzer format – from before and during the time the issue occurred.
2.Configuration files – for reviewing any special services that might be involved.
3.NPU command outputs – captured during the issue.
dia npu np7 hif-stats
dia npu np7 dce-drop-all
dia npu np7 dce-drop-all
dia npu np7 sse-stats
dia npu np7 pba
dia npu np7 pmon all
Regards
Bill
Hi BillH_FTNT
Thank you for the feedback, will share the dia outputs the challenge is will only send the current output or will have to wait for another drop and run those commands?
Hi Lwazi,
Could you please share some logs/CFP in advance ?
1.System/Event logs – preferably in syslog or FortiAnalyzer format – from before and during the time the issue occurred. (This is for last issue)
2.Configuration files – for reviewing any special services that might be involved.
3. Output of "exe tac report"
4. Output of "dia debug crashlog read"
Regards
Bill
Has it entered by any chance Conserve Mode? Look in logs for "Conserve" , also try on cli and look for Conserve Mode or anything matching the time of freezing:
diagnose debug crashlog read
Hi Yurisk
We did run the command with TAC and nothing was picked, the FW is actual idling no much traffic on it CPU less than 40%
Without logs indicating problem not much to debug, so if it is indeed Fortigate causing this then TAC ticket with gathering all the debug they find useful is the way.
Have you checked the connected gear as well - switches for loops, sudden FGT-related MAC changes, ports going up/down? To exclude it is a networking issues before/between Fortigates...
Hi Lwazi,
Enable comlog on the fortigate and see the kernel related output
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-the-COMLog-feature/ta-p/195390
Also connect to the console whenever you are rebooting to fix the issue.
Share those comlog latest output
Hi sjoshi
Can I run that command after roboot or have to wait for another crush..
Hi Lwazi,
If the comlog has been already enable before than it will store the kernel related output but if it was not enabled before you need to enable it and wait for the issue to get trigger.Also dont forget to take a console output while rebooting next time
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.