Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Shantilal1998
New Contributor III

User daemon-admin restored the image from ha-daemon

Hi Team,

 

Today I found a user event log as below 

 

User daemon-admin restored the image from ha-daemon 

 

And my firewall automatically upgraded from 7.4.5 to 7.4.6.

 

Kindly confirm whether it is genuine or not. 

10 REPLIES 10
Shantilal1998
New Contributor III

also found the below event also

 

User daemon-admin changed hostname global setting to <name> from cmdbsvr

Shantilal1998

Also, Why it also changed the hostname ?

 

dingjerry_FTNT

Hi @Shantilal1998 ,

 

For your FGT automatic upgrade from 7.4.5 to 7.4.6, it might be due to the new "automatic firmware upgrades" feature:

 

https://docs.fortinet.com/document/fortigate/7.4.5/administration-guide/369092

 

For the logs about "User daemon-admin", could you please share all of them?

Regards,

Jerry
Shantilal1998

These are the following logs generated for User daemon-admin:

 

User daemon-admin changed hostname global setting to VW-02 from cmdbsvr

User daemon-admin changed timeout global setting to 60m from cmdbsvr

 

Kindly share the reasons for the above logs...

 

 

dingjerry_FTNT

Hi @Shantilal1998 .

 

1) Is VW-02 a new hostname or it is an existing hostname?

2) Was the timeout global setting set to 60m before?

3) Is there any timestamp with those two logs?  And is there a system log for system rebooting?  

 

If yes for both, I guess the timestamp of the system reboot is earlier than those two "User daemon-admin" logs.

 

 

Regards,

Jerry
Shantilal1998

1) Is VW-02 a new hostname or it is an existing hostname?

    Yes, Hostname is same as before.

2) Was the timeout global setting set to 60m before?

Yes.

3) Is there any timestamp with those two logs?  And is there a system log for system rebooting?  

1.22 AM ---> the firmware was upgraded

1.26 AM ---> User daemon-admin changed hostname global setting to VW-02 from cmdbsvr

1.26 AM ---> User daemon-admin changed timeout global setting to 60m from cmdbsvr

1.26 AM --> The firewall was reboot..

 

Shantilal1998

And if the reboot is earlier then also what is the meaning of these events ?

dingjerry_FTNT

Hi @Shantilal1998 ,

 

All logs with "User daemon-admin" are due to system reboot.  And the system reboot was due to the automatic firmware upgrade.

 

When the system reboot is done, FGT system is using daemon-admin (system level admin account with full permissions) to copy and restore some/all configurations from the cmdb server.   The cmdb server is a daemon for saving the configuration.

 

That means you don't have to worry about the logs generated with daemon-admin.

Regards,

Jerry
Shantilal1998

But why only timeout and hostname ? any specific reason...

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors