Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RaphNiv
New Contributor

upgrade FortiOS 6.2.4 => src-vis crash

Hello all!

 

I updated FortiOS (E51) to 6.2.4, and since that time I have these errors in the event log: src-vis crash, this morning i can't to access the internet, I have reboot so that works again, I don't know if these two problems can be linked....

 

date=2020-06-23 time=14:01:29 logid="0100032546" type="event" subtype="system" level="warning" vd="root" eventtime=1592935290013368120 tz="-0400" logdesc="Application crashed" action="crash" msg="Pid: 02230, application: src-vis, Firmware: FortiGate-51E v6.2.4,build1112b1112,200511 (GA) (Release), Signal 11 received, Backtrace: [0x0112e052]" date=2020-06-23 time=13:59:29 logid="0100032546" type="event" subtype="system" level="warning" vd="root" eventtime=1592935170009465360 tz="-0400" logdesc="Application crashed" action="crash" msg="Pid: 02190, application: src-vis, Firmware: FortiGate-51E v6.2.4,build1112b1112,200511 (GA) (Release), Signal 11 received, Backtrace: [0x0112e052]" date=2020-06-23 time=13:57:29 logid="0100032546" type="event" subtype="system" level="warning" vd="root" eventtime=1592935050003591840 tz="-0400" logdesc="Application crashed" action="crash" msg="Pid: 02156, application: src-vis, Firmware: FortiGate-51E v6.2.4,build1112b1112,200511 (GA) (Release), Signal 11 received, Backtrace: [0x0112e052]" date=2020-06-23 time=13:56:51 logid="0100020027" type="event" subtype="system" level="information" vd="root" eventtime=1592935012235734000 tz="-0400" logdesc="Outdated report files deleted" msg="Delete 60 old report files" date=2020-06-23 time=13:55:29 logid="0100032546" type="event" subtype="system" level="warning" vd="root" eventtime=1592934929995863680 tz="-0400" logdesc="Application crashed" action="crash" msg="Pid: 02117, application: src-vis, Firmware: FortiGate-51E v6.2.4,build1112b1112,200511 (GA) (Release), Signal 11 received, Backtrace: [0x0112e052]" date=2020-06-23 time=13:54:19 logid="0100032011" type="event" subtype="system" level="notice" vd="root" eventtime=1592934859538470000 tz="-0400" logdesc="Disk log rolled" action="roll-log" reason="file-size" log="tlog" msg="Disk log has rolled."

Thanks.

 

9 REPLIES 9
lxzndr
New Contributor

Having the same issue here with the same error.  Haven't had to reboot yet though.

sw2090
Honored Contributor

hm I updated a 100D and a 300E from 6.0.8 to 6.2.4 and on both I do not have such event log entries.

However both FGT do not have traffic or internet at all atm ;)

I'll maybe do some more testing.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

src-vis is in long form source visibility signature package . Unfortunately I cannot find anythibng about what that is or does?

Would be interesting for testing to know wat that is for?

Can anyone of the Fortinet Gurus here answer this?

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
lxzndr
New Contributor

I received an answer from support, after submitting a crashlog, that ours is a known issue, bug id 0605838.  suggested roll back to previous version.

 

xgw
New Contributor

Having the same issue here too.  Began occurring after upgrading to 6.2.4.  Unfortunately, rolling back is not an option.

FlavioB
New Contributor III

Hi.

Are there any infos about what exactly "source visibility signature package" is? No info found yet...

Thanks,

Flavio.

xgw
New Contributor

I'm pretty sure it is the daemon that populates the Users & Devices -> Device Inventory portion of the GUI

Since I couldn't downgrade, I had to disable it.  Afterwards, I no longer receive any data in that section of the GUI, sorry I don't know the proper name for it.

boneyard
Valued Contributor

you enable (and disable) with the device identification on an interface.

 

the crashlog will show you which traffic and source IP causes it, so you know on which interface to disable it.

 

6.2.6. should fix this.

FlavioB
New Contributor III

Yes, 6.2.6 is fixing this apparently (been told so by TAC).

I'll upgrade these days and check.

F.

Labels
Top Kudoed Authors