" The log disk has not been checked for errors for 57 mounts. You should run ' diag sys file-system fsfix' . If unsuccessful, you can also try running ' diag sys file-system fsrebuild' ."What if I try to run the ' diag sys file-system fsfix' or ' diag sys file-system fsrebuild' ? Is my FA gonna be just fine? What are the risks if these commands (the command must be running under CLI Console, right?) failed to run? And how long the time will be taken to execute of these commands? (Our FA Harddisk' s size is 916.89GB (Usage: 5.22GB of 916.89GB). 2.
" The configured primary DNS server is not reachable. A valid DNS server is required for resolving IP addresses to hostnames in reports." " The configured secondary DNS server is not reachable. A valid DNS server is required for resolving IP addresses to hostnames in reports."I' ve tried to use local and supplied DNS (DNS that supplied from our ISP). But we still received the same errors. How to fix it? 3.
" Failed to transfer file 1503:1628870483:104 to FortiAnalyzer: No such file or directory." " The system has deactivated session fail mode" " The system has entered conserve mode" " The system has activated session fail mode" " The system has entered system conserve mode" " The system exited conserve mode"We received tons of these errors. What does it means and how to fix them?
Hi, and welcome to the forums!Thank you for the warm welcome
You seem to have serious trouble with your FAZ.That' s what I' m worried about
First of all, I would recommend you get professional help to guide you. Depending on your service contract you may open a support case with Fortinet, especially if it includes phone support or web chat.To be honest, I' m new with FAZ. FYI, the firmware version of our FAZ is: FortiAnalyzer-1000B v4.0,build0208 (MR2 Patch 1) and its VM Plugins and VM Engine are: VM Plugins 0.000 (Updated 2005-11-01) VM Engine 0.000 (Updated 2005-11-01) It' s quite an old version, right? Looks like my boss didn' t want to continue purchasing license or contract from Fortinet Technical Support. But I' ll ask him to continue receiving updates as soon as I know how to operate FAZ. BTW, is the firmware of our FAZ using the last version right now (FortiAnalyzer-1000B v4.0,build0208 (MR2 Patch 1))? Where to find or how to know the latest firmware releases from Fortinet' s products? And is it upgrading a firmware (espesially for our FAZ) will charged us?
It looks to me like you' ve had a lot of power outages which made the FAZ reboot. Could that be the case here?You' re almost right. Because of I' m new to FAZ, I' m very often rebooted the machine (FAZ) (from web-based manager). Such as trying to change the database storage from Local database to to the default proprietary indexed file storage system. Our default FAZ' s settings to use to stores the log data is Local database (PostgreSQL). I' m very often doing this (changing the database location and reboot the machine) because of as the manual said (FortiAnalyzerâ„¢ Administration Guide Version 4.0 MR2 21 March 2011 Revision 13),
You can only add a Top Traffic/Top Web Traffic/Top Email Traffic/Top FTP Traffic/Top IM/P2P Traffic/Virus Activity/Intrusion Activity widget when you selected the proprietary indexed file storage systemEvery time I tried to change the database storage location, I' ll reboot the machine. And it looks like nothing changed from our FAZ' s traffics (Top Traffic/Top Web Traffic/Top Email Traffic/Top FTP Traffic/Top IM/P2P Traffic/Virus Activity/Intrusion Activity widget). Just same. Or should I follow the guide revision 5 (FortiAnalyzer™ Administration Guide Version 4.0 MR2 10 June 2010 Revision 5)? I' m also have another question. Sometimes, I can view the expanded details for one of the widget’s items by clicking the + button (viewed by Device, Destination, Log Details etc.) It' s very often that I can' t view them. The widgets that I can always view its all expanded detail is only two: Virus Activity and Instrusion Activity). Is it goes like that? Because of I can' t view another widgets details, I' m also very often reboot the machine (I can only view them just for a while (maybe 5 or 10 minutes)).
You should take precautions for an extended downtime of the FAZ and execute the first diag command from the CLI. This is like a ' fsck' on a UNIX machine meaning it might take some time. I will not give in to estimate what that would be in your case, more likely hours than minutes. This should fix the apparent file system errors.Is the machine/harddisk gonna be ok? I mean, it will not be error (our FAZ can' t operate anymore)?
It' s just what it says. Either the DNS addresses are wrong or the FAZ cannot connect to them. The route to the DNS might be missing, or a firewall in between might block this traffic...there are many options but all of them are straight forward and you should be able to resolve this.I' ve asked our network team and they said it' s a firewall blocked the traffic.
Your FAZ ran out of memory. If memory usage increases beyond 80% the FAZ (like a Fortigate) begins to shut down less important services. During this emergency situation a file needed to be quarantined or a log file had to be rolled over and the device just couldn' t do it. You should check what makes the FAZ go screaming like this. It is definitely not a situation to live with and ignore.How to check it? I' m new with FAZ. I just read the manual. Maybe I' ll ask my boss to train me with FAZ technical.
FAZ-800 # diagnose sys fsystem Log disk partition table type is MSDOS. Log disk is ext3 file system. Log disk directories are indexed.Hope that helps.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
' internal indexed file system' is identical to the ' Local database' , Regarding the widget, some allow for drill down and others don' t.About the DNS, I think it was our company policy that won' t allowed it. And I think there is something wrong with the Alert Message Console' s widget. Normally, this widget will showing message There is no serious outstanding ..... or something like that, if there are no messages (Warning, Error, Critical, Emergency etc.), appears. I' ve uploaded the picture. I think I will try to run the command ' diag sys file-system fsfix' . I' ll backup my FAZ configuration first. I hope that all of you guys will keep continuing assist or helping or guide me regarding to my FAZ. Oh yes, how to run a command in the CLI like when I want to change the severity level of alert mesage console to emergency. I' m always received error: command parse error before ' alert_console' Command fail. Return code 1 I' ve uploaded the picture also. I' m very often receiving error message like this. Except for simple command like execute ping etc. And because of the Alert Message Console widget not showing " There is no serious outstanding ....." message anymore, then I try to run the command diagnose sys dashboard rebuild-reports which I believe this command will fix my problem. But just same :( Please help me...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.