Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
salsero_gallego
New Contributor II

Fortigate dos not reboot

Hi all I have a problem with a 60C in a remote office. The fortigate dos not work correct. I need to reboot the box. SSH access works, but I can' t reboot the Firewall. ########## hostname-fortigate # execute reboot This operation will reboot the system ! Do you want to continue? (y/n)y System is rebooting... ########## But the Fortigate dos not reboot. In the office there is no one who can turn off/on the box. Any ideas?
19 REPLIES 19
emnoc
Esteemed Contributor III

Have you tried the WEbGui, and does it exhibit the same issue? Also what does any log events show? lastly, I guess you can find some one local to pull the AC code

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
billp
Contributor

Not that this would help now, but I believe you can buy inexpensive IP-aware power strips that can cycle power remotely. Just a thought in case you run into this again.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
salsero_gallego
New Contributor II

Have you tried the WEbGui
WebGUI is down. One of the point what dos not work. I need a command via SSH, that enforce a reboot. Without any checks/stop/shutdown process.
FortiRack_Eric
New Contributor III

first perform a diag sys top and then press M to order on memory usage and post back here. also check diag hardware sys shm and post output here

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
ejhardin
Contributor

I' m guessing here but I bet that the diag sys top will show a lot of process that are in a " z" state for zombie. The reason that it will not reboot is because the cmdb process is in a " z" state. I had the same issue with a 60c that was in china. Webgui was up and then was down.... I was able to pass some traffic and ssh into the box but it would not respond to any commands even the secret backdoor root commands. I called Fortinet and was pushed up to a dev guy and he tired to preform the last restore command and no go. If you can manually reboot it I bet you have a 50/50 change of it not booting. Fortigate shipped a replacement asap. You really not have a lot of options.
salsero_gallego
New Contributor II

Yesterday afternoon there was a short power failure on site. The firewall has then booted normally. I have now normally access to the box. I had yesterday the same problem on an other 60C. But there were people onsite and have rebooted the box. After many tests, we found that the box is overloaded with VPN encryption. On our 60C we run 3-5 VPNs. When 2-3 of them are heavily used, then the 60C crash. Now I have done on the Phase 1 and Phase 2 encryption " lower" and now run the 60C with the all VPNs. Strange that a VPN on a Fortigate can be killed the box ...
Carl_Wallmark
Valued Contributor

What encryption did you use? Some of them is software only and not hardware accelerated.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
salsero_gallego
New Contributor II

Now AES128 - SHA1 (for both, Ph1 and Ph2). Before it was higher.
emnoc
Esteemed Contributor III

Will now you found the problem, i highly doubt changing the encryption cipher is going to make that difference with the fortiasic CP offloading for vpn traffic. You need to conduct a budget estimate of vpn traffic and other tasks and functions that you are doing VPN AV overall traffic flow etc.... fwiw the 60c is only rated at 70mbps of VPN traffic and that is over estimated by fortinet imho & with no other traffic types. So what other tasks are you doing? Worst case you might need to look at upgrading to a bigger box.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors