Hello,
I'm having an issue on my FAZ VM64.
FortiAnalyzer-VM # execute top top_bin - 09:19:52 up 3 days, 18:11, 0 users, load average: 4.71, 5.79, 6.68 Tasks: 187 total, 1 running, 186 sleeping, 0 stopped, 0 zombie Cpu(s): 4.6%us, 33.7%sy, 0.0%ni, 61.6%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st Mem: 16450692k total, 16312652k used, 138040k free, 74544k buffers Swap: 2076536k total, 1043740k used, 1032796k free, 12492296k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 23984 root 20 0 616m 66m 9320 S 299 0.4 53:09.05 oftpd 10 root 20 0 0 0 0 S 1 0.0 2:18.29 kworker/0:1 16 root 20 0 0 0 0 S 0 0.0 0:02.25 ksoftirqd/3 64 root 20 0 0 0 0 S 0 0.0 1:31.54 kworker/6:1
Process oftpd eating all cpu. When I debug this process I have the follow output:
diagnose debug application oftpd 99 oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully] oftps.c:521: SSL_write error rc[5] state[SSL negotiation finished successfully]
Then The logs stops to be write on FAZ, only get back when I restart the process oftpd.
Has anyone know What should be done to solve?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
how many FGTs send log to this VM? and reliable TCP logging enabled?
is this issue noticed after upgrade to 5.2.4 or also happens on old release?
can you provide me " diag dlp-archives statistics show", "diag log device", "diag system print df", you can also open a ticket and attach these diag info, and let me know the ticket ID so I can follow up
Thanks
Simon
Hello,
A workaround that I found, was disable Encrypt Log Transmission from all devices that send log to this FAZ. Then the process stops to use all CPU, and everthing works fine. The problem regarding this workaround is concern security.
I 'll open a ticket and let you know.
There are 138 devices.
It was happen also in old release 5.0.11, then I tried to upgrade to 5.2.4 but this issue still there.
FortiAnalyzer-VM # diagnose dlp-archives statistics show
Statistics since 2015-10-15 14:08:45
Type Files Duplicates Bytes
---------------------------------------------------------------
Web_Archive 0 0 0
Secure_Web_Archive 0 0 0
Email_Archive 0 0 0
File_Transfer_Archive 0 0 0
IM_Archive 0 0 0
MMS_Archive 0 0 0
AV_Quarantine 0 0 0
IPS_Packets 0 0 0
--------------------------------------------------------------
Total 0 0 0
FortiAnalyzer-VM #
diag system print df
Filesystem 1K-blocks Used Available Use% Mounted on
none 15988260 4 15988256 0% /dev/shm
none 65536 52 65484 0% /tmp
/dev/sda1 516040 70348 445692 14% /data
/dev/mdvg/mdlv 9723619512 4802102396 4921517116 49% /var
/dev/mdvg/mdlv 9723619512 4802102396 4921517116 49% /drive0
/dev/mdvg/mdlv 9723619512 4802102396 4921517116 49% /Storage
/dev/loop0 9911 1121 8278 12% /var/dm/tcl-root
none 1048576 0 1048576 0% /drive0/tmp/sql_bat
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.