Sometimes the Fortigate devices has problem and they do not want to boot anymore (my experience is 2 from about 50 Boxes). Sometimes we have to buy a new one, but in this case I mention we should not.
The message crc error is a problem that we can solve alone.
Official link for RIM:
http://emea.fortinet.net/fortinet/rim/index.php
FGT50B3G10622908 # FGT50B (14:15-10.01.2008) Ver:04000010 Serial number:FGT50B3G10622759 RAM activation Total RAM: 256MB Enabling cache...Done. Scanning PCI bus...Done. Allocating PCI resources...Done. Enabling PCI resources...Done. Zeroing IRQ settings...Done. Verifying PIRQ tables...Done. Enabling Interrupts...Done. Boot up, boot device capacity: 64MB. Press any key to display configuration menu... ...... Reading boot image 1319487 bytes. Initializing firewall...crc errorINITTAR: falling back to normal initrd... crc errorFAT: bogus logical sector size 0 Kernel panic: VFS: Unable to mount root fs on 01:00 FGT50B (14:15-10.01.2008) Ver:04000010 Serial number:FGT50B3G10622759 RAM activation Total RAM: 256MB Enabling cache...Done. Scanning PCI bus...Done. Allocating PCI resources...Done. Enabling PCI resources...Done. Zeroing IRQ settings...Done. Verifying PIRQ tables...Done. Enabling Interrupts...Done. Boot up, boot device capacity: 64MB. Press any key to display configuration menu... .... |
1. Hit any key to get in boot menu
[G]: Get firmware image from TFTP server. [F]: Format boot device. [I]: Configuration and information. [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter Selection [G]: Enter G,F,I,Q,or H: |
2. Enter capital F
All data will be erased,continue:[Y/N]? Formatting boot device... ................................ Format boot device completed. |
3. Enter capital G and define TFTP SErver IP local IP and the image name
The Input fields are not the bests one, you cannot modify any character if you type it wrongly. Be carefull or restart the box if something mistyped (power off/on..)
In the messages we can read “Please connect TFTP server to Ethernet port “3”.”. This is the only port that works.
Enter G,F,I,Q,or H: [G]: Get firmware image from TFTP server. [F]: Format boot device. [I]: Configuration and information. [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter Selection [G]: Enter G,F,I,Q,or H: Please connect TFTP server to Ethernet port "3". Enter TFTP server address [192.168.1.168]: 10.248.100.64 Enter local address [192.168.1.188]: 10.248.100.16 Enter firmware image file name [image.out]: image.out MAC:00090FDE3E70 ################### Total 20563014 bytes data downloaded. Verifying the integrity of the firmware image. Total 28288kB unzipped. |
4. Save as default (if it is newer as the factory image)
Save as Default firmware/Run image without saving:[D/R]?D Programming the boot device now. ........................... Reading boot image 1346508 bytes. Initializing firewall... System is started. Formating shared data partition ... done! FGT50B3G10622759 login: |
What do we have in a Fortigate 50B:
This is definetly an SMB device, I would wonder what happens if the ips and other utm features are enabled and vpn is configured, would it be much more slower?
OS image name : flatkc vendor_id : AuthenticAMD cpu family : 5 model : 10 model name : Geode(TM) Integrated Processor by AMD PCS stepping : 2 cpu MHz : 433.201 cache size : 128 KB memory : SDRAM 256MB 333MHz IDE device channel 0 drive 0: No device IDE device channel 0 drive 1: No device IDE device channel 1 drive 0: No device IDE device channel 1 drive 1: No device |
david
October 26, 2012
thanks!
Jim Scheirer
October 15, 2013
Another thing to add is boxes that use compact flash cards can get crc errors and no matter how many times you reflash you still get an error. this is the result of a bad CF card. You can replace the CF card with a new one and perform the same procedure defined above and it will be back to working order. Of course don’t do this if you are under warranty because they will replace it for free. Also, the CF card is a real bugger to remove as they “tactifully” placed a heat sink close enough to make it very difficult to remove (but not impossible)
itsecworks
October 15, 2013
You are right, everything is possible :-)
Ismael Cruz
August 26, 2014
Do you have any idea how remove the CF CARD
itsecworks
August 30, 2014
Sorry, No.