Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rafael_Rosseto
New Contributor

Oftpd lots CPU 5.2.4

Hello,

I'm having an issue on my FAZ VM64.

 

FortiAnalyzer-VM # execute top top_bin - 09:19:52 up 3 days, 18:11,  0 users,  load average: 4.71, 5.79, 6.68 Tasks: 187 total,   1 running, 186 sleeping,   0 stopped,   0 zombie Cpu(s):  4.6%us, 33.7%sy,  0.0%ni, 61.6%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st Mem:  16450692k total, 16312652k used,   138040k free,    74544k buffers Swap:  2076536k total,  1043740k used,  1032796k free, 12492296k cached   PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND 23984 root      20   0  616m  66m 9320 S  299  0.4  53:09.05 oftpd    10 root      20   0     0    0    0 S    1  0.0   2:18.29 kworker/0:1    16 root      20   0     0    0    0 S    0  0.0   0:02.25 ksoftirqd/3    64 root      20   0     0    0    0 S    0  0.0   1:31.54 kworker/6:1

Process oftpd eating all cpu. When I debug this process I have the follow output:

 

diagnose debug application oftpd 99 oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully]

Then The logs stops to be write on FAZ, only get back when I restart the process oftpd.

 

Has anyone know What should be done to solve?

 

2 REPLIES 2
scao_FTNT
Staff
Staff

how many FGTs send log to this VM? and reliable TCP logging enabled?

 

is this issue noticed after upgrade to 5.2.4 or also happens on old release?

 

can you provide me " diag dlp-archives statistics show", "diag log device", "diag system print df", you can also open a ticket and attach these diag info, and let me know the ticket ID so I can follow up

 

Thanks

 

Simon

Rafael_Rosseto

Hello,

 

A workaround that I found, was disable Encrypt Log Transmission from all devices that send log to this FAZ. Then the process stops to use all CPU, and everthing works fine. The problem regarding this workaround is concern security.

 

I 'll open a ticket and let you know.

 

There are 138 devices.

 

It was happen also in old release 5.0.11, then I tried to upgrade to 5.2.4 but this issue still there.

 

FortiAnalyzer-VM # diagnose dlp-archives statistics show 
Statistics since 2015-10-15 14:08:45
	 Type 		 Files 		 Duplicates 		 Bytes
	---------------------------------------------------------------
	 Web_Archive 	 0 		 0 		 0
	 Secure_Web_Archive 	 0 		 0 		 0
	 Email_Archive 	 0 		 0 		 0
	 File_Transfer_Archive 	 0 		 0 		 0
	 IM_Archive 	 0 		 0 		 0
	 MMS_Archive 	 0 		 0 		 0
	 AV_Quarantine 	 0 		 0 		 0
	 IPS_Packets 	 0 		 0 		 0
	--------------------------------------------------------------
	 Total 		 0 		 0 		 0
 
FortiAnalyzer-VM #  



diag system print df
Filesystem           1K-blocks      Used Available Use% Mounted on
none                  15988260         4  15988256   0% /dev/shm
none                     65536        52     65484   0% /tmp
/dev/sda1               516040     70348    445692  14% /data
/dev/mdvg/mdlv       9723619512 4802102396 4921517116  49% /var
/dev/mdvg/mdlv       9723619512 4802102396 4921517116  49% /drive0
/dev/mdvg/mdlv       9723619512 4802102396 4921517116  49% /Storage
/dev/loop0                9911      1121      8278  12% /var/dm/tcl-root
none                   1048576         0   1048576   0% /drive0/tmp/sql_bat
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors