Hi Guys
Happy new year.
This morning I found fortigate blocked (fortigate 300E), it's in HA mode Active Active. Firewall was reachable but all the traffic was locked because ( i think) there was an overlaod of memory 88% (i think RAM memory). The faster solution was been to restart device via cli.
Now the backup fortigate is running as master and memory is running on 46%
I looking for any issue or any details about this block via web interface but I didn't find anything. I don't know if it's necessary to implement any config.
I noted an issue:
I configured syslog server via cli and I enabled only warning severity and lower 1 mounth ago.
On Syslog server I don't find any log over 29/12/21 at 14:47 o'clock.
After reboot syslog server restart to receive logs from Fortigate, from logs I don't find anything.
On fortigate I disabled save of logs on local memory, is it correct?
Where I can looking for the issue? Is there any cli command to looking for the issue?
I know it's general request but I don't know how I can start.
Marco
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There are 3 places to look:
- system event logs
- crashlog (may be cleared at reboot or if memory logging disabled)
- comlog (if it was enabled)
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-COMLog-feature/ta-p/195390?exte...
If you can't find it in these places, you won't be able to find out.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.