TAC Support Pre-Flight Services

Instant Root Cause.
Zero TAC Delays.

Get clear, actionable answers for FortiGate issues — before you open a TAC case. Ferrite correlates logs, configs, and known CVEs to pinpoint the root cause in minutes, not days.

Find root cause in minutes
Reduce TAC case volume
Stay ahead with CVE insights
Monitoring Scripts
No customer data required Read-only access Safe and secure
Ferrite Script Monitoring SIMULATION · NOMINAL
CPU LOAD 38% NOMINAL CORE DIAGNOSTIC ARRAY · 01 TELEMETRY CHANNEL 7A · ACTIVE
CPU distribution is balanced across all 16 active cores.
01 · The problem

Incident response loses time in complexity.

Three critical bottlenecks delay incident resolution: fragmented evidence across dense TAC reports, silent configuration drift over time and unverified PSIRT vulnerability exposure.

Fragmented TAC evidence

Raw diagnostic dumps split critical CPU, memory and session signals across dozens of unlinked CLI tables, delaying triage.

Hidden configuration drift

Undocumented changes between snapshots trigger unexpected outages, policy bypasses and HA cluster desynchronization.

Unverified PSIRT exposure

Knowing a CVE exists is not enough. You need instant proof of whether your active firmware, hardware models and configurations are exposed.

02 · The solution

From fragmented signals to evidence-backed progressions.

Ferrite automates the extraction, correlation and sanitization of FortiOS telemetry. Move from raw evidence to verified remediation with complete audit proof.

01 · Ingestion Ingest evidence safely

Parse 15,000+ line configs and diagnostic logs in your browser with zero data leakage.

02 · Correlation Correlate root causes

Automatically align memory consumption patterns, crashlog traces and policy changes across time.

03 · Action Execute verified fixes

Generate sanitized configs, audit-ready compliance reports and step-by-step field runbooks.

03 · Dual-Engine Showcase · Air-Gap Sanitization & Live Telemetry Feed

Air-gap sanitization & real-time telemetry stream recorder.

Drop diagnostic bundles for client-side privacy sanitization under DORA Article 28, or connect your live FortiOS stream to inspect real-time diagnostics, record session logs to file, and drive incident telemetry in real time.

100% In-Browser RAM
Zero Data Egress

Reduce Data Leakage Risk

100% Client-side execution
01 Upload
02 Inspect
03 Sanitize
04 Review
05 Export
CONFIG SANITIZATION STREAM
AIR-GAP ZERO-EGRESS PARSER

Zero-Egress Stream Parser Standby

Waiting for configuration stream. Select a FortiGate backup or launch an instant demo preset on the left to observe live credential redaction in RAM.

Lines0
Safe0
Masked ?0
Removed ?0
Review0
Tier 2 / Enterprise Results Workspace
Normal visitors have Free Scrubber & Basic Monitoring Script access. Sign in for full root-cause correlation and TAC export.

MSG-CHTIAFW001.conf SANITIZED · 0.0 KB EGRESS

15,482 lines 8 removed 42 masked 2 review
LOCAL IN-MEMORY PARSER STREAM LOG 100% In-Browser RAM · Zero Server Upload
[000001] # FortiGate Configuration Stream - Parsed & Sanitized in RAM
[000002] config system global -> set hostname [TOKENIZED]
[000014] config system admin -> password [REDACTED_SECRET]
[000184] config system ha -> group-secret [REDACTED_SECRET]
[001420] config firewall policy -> edit 1 -> set inspection-mode flow [VERIFIED]
SAFE TO SHARE HEALTH 72/100 REVIEW 2 RUNBOOKS 3 0.0 KB EGRESS TAC READY
Recommended next action: Review 2 identity-bearing values before external distribution
HIGHEST LEVERAGE NEXT STEP

Review 2 identity-bearing values before external distribution

Standard privacy profile preserved public subnets and device hostnames. Triage these items in the Privacy Queue to redact or confirm before sharing with third parties.

Autonomous Diagnostic Matrix // 4-Pillar Setup Classification Click any card to inspect findings
MISCONFIGURATIONS 2 FLAGGED
Proxy Inspection on 2GB RAM & HA Priority Mirroring

Hardware ceiling exceeded (40F: 2GB RAM) and identical HA priority risks split-brain.

➜ Inspect 2 Misconfigurations →
EDGE-CASES 1 DETECTED
IPsec Re-Key / Route Flap Race Condition

High concurrent TCP traffic load under 85% CPU introduces packet drop risk during re-key.

➜ Inspect 1 Edge Case →
KNOWN ISSUES (BUGS) 1 IDENTIFIED
Bug ID 0984712 (WAD Daemon Leak in 7.4.2)

Firmware defect in FortiOS v7.4.2 build2829 causing memory bloat during HTTP/2 multiplexed streams.

➜ Inspect Known Issue →
RESOLVED & HEALTHY 3 VERIFIED
Security Fabric (CSF) & SAML SSO Verified

Cryptographic HMAC tokens, SAML identity certificates, and CVE-2024-21762 mitigations confirmed compliant.

✓ View Healthy Controls →
Diagnostic fidelity: HIGH. Profile: Standard. Technical relationships remain traceable for TAC.
CRITICAL RISK RULE-201//-RCA

Proxy Inspection Active on 2GB Architecture

MSG-CHTIAFW001.conf (Line 1,420)

FortiOS 7.4+ Admin Guide strictly deprecates Proxy mode on models with ≤2GB RAM due to memory overhead. Triggers conserve mode red zone (LogID 0100032001) and drops sessions.

config firewall policy
    edit 1
        set inspection-mode proxy
    next
end

LogID 0100032001: Red-zone conserve mode engaged at 88% RAM. Proxy workers restricted session table allocations.

config firewall policy
    edit 1
        set inspection-mode flow
    next
    edit 2
        set inspection-mode flow
    next
end
Dedicated Break-Fix Support & Non-Public Bug Escalation Dossier

Structured expected-vs-observed delta analysis ready for FortiCare Level-3 escalation.

92% TIER-3 TAC READY
Non-Public Bug & Zero-Day Diagnostic Disclaimer:
If anomalous behavior persists after verifying baseline settings, there is a high probability of an undocumented software defect, kernel race condition, or unreleased firmware regression. The matrix below records verified expected settings against observed unexpected anomalies to initiate formal escalation.
EXPECTED SETTINGS & BEHAVIOR (GOLDEN BASELINE) OBSERVED ANOMALIES & IRREGULARITIES
  • Flow-mode AV/IPS profile operating within <70% RAM ceiling on FortiGate-40F.
  • Deterministic asymmetric HA priority weighting (Node A: 200, Node B: 100).
  • Cooperative Security Fabric (CSF) heartbeat exchange with synced HMAC tokens.
  • 4 Policies configured for Proxy DPI causing 88% Red-Zone Conserve Mode (LogID 0100032001).
  • Identical HA priority (100/100) with override disable creating split-brain exposure.
  • Daemon memory growth anomaly in WAD process under concurrent SSL negotiations.
Artifact: FORTICARE_TAC_LEVEL3_PACKAGE.zip
Detect / Monitor / Respond / Stay Ahead

FortiGate Live Tripwire &
Real-Time Monitoring Scripts

Automate live diagnostic capture directly from your Tera Term serial/SSH console session. Choose between lightweight continuous baseline pollers (Tier 1) and an event-driven 5-stage dual-tripwire forensics engine (Tier 2).

3-STEP WORKFLOW
01
CONNECT

Open Tera Term SSH or Serial Console to FortiGate.

02
EXECUTE

Select Control → Macro and pick .ttl script.

03
SANITIZE

Drop generated .log into Ferrite Scrubber above before TAC submission.

DIAGNOSTICS
LOGS
STRONGER
TOMORROW
Tier 1 / Free / Public

Continuous Baseline & Diagnostic Pollers

Lightweight, non-intrusive Tera Term polling scripts for baseline performance capture, routine health monitoring, and crashlog extraction.

2 SCRIPTS INCLUDED
ssh: admin@fgt-60f
CPU: 2% usr, 98% idle
Mem: 38% [conserve: OK]
FGT-60F # diag top-mem 3
 wad (1284):      42MB
 ipsengine (1402):88MB
FGT-60F # diag sys session stat
misc: count=142 rate=8/s
FGT-60F # diag debug crashlog read
23:59:14 log=0 crashes
FGT-60F # get hardware status
CPU: 44°C | Fan1: 4200 RPM
FGT-60F # _
TTL MACRO LOW-LEVEL LOOPER

01basic_monitoring_script.ttl

Continuous polling diagnostic macro executing mpstat, top-mem 99, hardware sysinfo conserve, and debug crashlog read.

ssh: admin@fgt-edge
Run: 42d 18h | 0U 1S 99I
Mem: 1874M tot, 712M used
 wad       1284 S 0.8 4.2
 ipsengine 1402 S 0.4 8.1
 httpsd    1890 S 0.0 2.1
FGT-EDGE # diag sys session stat
count=320 active=312
FGT-EDGE # diag sys top 1 3
Run: 42d 18h | 1U 1S 98I
Mem: 1874M tot, 715M used
 wad       1284 S 1.2 4.3
FGT-EDGE # _
TTL MACRO RAPID SNAPSHOT

02ferrite_quick_poll.ttl

High-speed 10s rolling snapshot poller for top-process accounting (diagnose sys top) and non-intrusive baseline logging.

Tier 2 / Advanced / Paid (Staging & Labs)

Dual-Tripwire Auto-Capture & iRCA Engine

Event-driven 5-stage forensics engine designed specifically for staging, QA reproduction, and lab verification. Automatically arms deep forensics upon tripwire breach.

autocapture_v12_2.ttl MEMBER LOGIN REQUIRED
Gated for Visitors: Staging scripts & tripwire packages require a Member / Enterprise login. Sign in or enter work email to access.
Dual Tripwire Arms on conserve mode (>70%), memory growth (+5%/hr), or IO/SoftIRQ spikes.
Process Deep Dive Extracts WAD worker traces, IPS engine pools & kernel slab allocator dumps.
HA Split-Brain Drift Monitors checksum parity and session synchronization health.
08 · Field Guidance & Knowledge Base

Interactive Runbook Knowledge Base & PSIRT Intelligence

Immediate access to high-severity Fortinet PSIRT impact assessments and 25 interactive diagnostic runbooks covering conserve mode, process crashes, HA split-brain, BGP routing and hardware RMA verification.

PSIRT Intelligence

121+ CVES INDEXED

Verified FortiGuard advisory context and historical CVE impact.

FG-IR-26-141 Critical · CVSS 9.1

Second-Order OS Command Injection via JSON Input on start VNC feature — FortiSandbox.

Advisory snapshot baseline: 2026-06-09

Interactive Knowledge Base

30 RUNBOOKS LIVE · CRON SYNCED

Step-by-step diagnostic workflows with command verification, operational cautions and exportable audit records.

Off-Site Tips

Prepare, collect and review evidence before you act.

Remote Ops

Investigate recurring issues and process isolation.

On-Site Tips

Resolve hardware, optics, power and RMA preparation.

HOW FERRITAAS WORKS

Triage as a Service (TaaS) for FortiGate Incidents
and Maintenance Windows

Whether you're troubleshooting an active outage, verifying a 2:00 AM maintenance window, or tracking longitudinal configuration drift, FerritaaS isolates root causes without exposing customer data.

PATH 02 MAINTENANCE & DRIFT

Reports & Maintenance Windows

"I need to understand what changed over time."

Compare T₀ (Pre-Change) → T₁ (Execution) → T₂ (Post-Verification) baselines or SolarWinds NCM nightly backup revisions. Audit firmware upgrades, detect silent HA split-brain divergence, and prove zero configuration drift.

Verify Maintenance Baseline →
PATH 03 REAL-TIME TELEMETRY

Live Incident Stream

"The problem disappears before I capture it."

Stream real-time FortiOS console telemetry via direct USB cable (zero-install), Network SSH, or air-gapped Tera Term log watcher. Automatically triggers forensics before memory resets.

Just need to sanitize a configuration? Strip passwords, PSKs, certificates & subnets locally in memory before vendor submission.
Open Free Air-Gap Scrubber →
09 · Stage 02A · High-Availability Cluster & Split-Brain Verification

Verify 0% silent checksum de-sync & split-brain hazards across HA cluster nodes.

Automated cluster topology inspector verifies active-passive / active-active FortiGate clusters, isolates heartbeat communication health, normalizes member-local fields and generates instant FortiOS HA auto-remediation scripts under DORA Articles 11 & 12.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
STAGE 02A · HA CLUSTER INSPECTION ENGINE

Cluster Member Ingested: MSG-CHTIAFW001 · Awaiting Peer Node

Active FortiOS High Availability parameters detected in MSG-CHTIAFW001.conf. To calculate deterministic split-brain hazard and delta checksum divergence, ingest the peer cluster member (Member B).

HA NODE 1 OF 2 · AWAITING PEER
FAILOVER SANDBOX Simulate Primary Node Outage & Traffic Blackhole
Cluster Topology
Active-Passive (A-P)
HA Group ID
Group 12
Heartbeat & Monitored
port1, wan1 (Monitored)
Split-Brain Risk Index
Awaiting Peer Member B
Single HA Cluster Member Ingested: Primary Node (MSG-CHTIAFW001)

This firewall is configured as an HA cluster node (Active-Passive, Priority: 200). To compare intra-cluster checksums and verify 0% silent drift against the secondary peer node, ingest Member B.

10 · Stage 02B · Pre/Post-Flight Maintenance Window & Config Change Verifier

Deterministic pre/post-flight verification for FortiOS change windows.

Audit firmware upgrades (T₀ Pre-Check ➔ T₁ Post-Upgrade), detect silent HA split-brain desync, verify BGP route parity, flag deprecated syntax, and generate auditable CAB / ITIL change verification dossiers.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
MAINTENANCE SAFETY
98.2% CAB Safe Score
HA CHECKSUM PARITY Δ
100% Cluster Sync Match
DEPRECATED SYNTAX Δ
1 Flag Proxy-Mode on 2GB
VERIFIED DELTA
+461 Lines T₀ ➔ T₁ Upgraded
WORKSPACE PERSPECTIVE:
PRE/POST-FLIGHT MAINTENANCE WINDOW VERIFIER
FILTER DELTA EVIDENCE BY CONFIGURATION DOMAIN:
CONFIGURATION DELTA FORENSICS (T2 ➔ T3)
GENERATED RECOVERY PLAN Target: T3 INCIDENT ➔ T2 PRE-CHANGE BASELINE
RESTORE TARGET:
4 Commands · 2 Firewall Policies removed · 1 Static Route reverted · 14 Objects pruned
# Automated Rollback Script to restore T2 (Apr 15 Pre-Change Baseline)
config router static
  edit 14
    set gateway 10.10.40.1
  next
  delete 15
end
config firewall policy
  delete 108
  delete 109
end
Syntax Validated Target Objects Found in T3 Commands Restore Selected Baseline Engineer Review Required Before Execution
11 · Stage 03 · Access Control & Policy Table Hygiene

Eliminate shadowed rules, reclaim kernel RAM & resolve ACL conflicts.

Autonomous policy hygiene engine parses access control lists, identifies unreachable rules, flags orphaned address objects and generates instant 1-click FortiOS CLI pruning scripts under DORA Article 9.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
STAGE 03 · AUTONOMOUS POLICY HYGIENE ENGINE

Firewall Access Control & Shadow Rule Collision Matrix

Inspect shadowed rules, resolve port overlaps, identify unreferenced objects and calculate kernel RAM reclaimable across policy lookup tables.

TABLE EFFICIENCY
84% → 98%
18 FINDINGS DETECTED
Shadowed (Unreachable) 14 Rules
Orphaned Objects 82 Objects
Port Overlaps 6 Pairs
Expired Contractor Rules 3 Rules
Reclaimable Kernel RAM ~4.8 MB
LIVE DYNAMIC PRUNING SCRIPT 18 Items Selected for Pruning
✓ Estimated Memory Savings: ~4.8 MB RAM

          
12 · Stage 04 · Golden Baseline & CIS / DORA Compliance Auditor

Automated Golden Baseline, CIS Benchmark v1.2 & EU DORA resilience audit.

Continuous compliance verification engine audits running configurations against hardening standards (CIS FortiOS 7.x Benchmark, EU Regulation 2022/2554 DORA), flags security deviations and generates 1-click remediation scripts.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
STAGE 04 · GOLDEN BASELINE & COMPLIANCE SENTINEL

Regulatory Hardening & Golden Baseline Auditor

Continuous compliance verification engine audits FortiOS configurations against technical controls in CIS FortiOS Benchmark, EU DORA (Regulation 2022/2554) and PCI-DSS 4.0 standards with synthesized remediation scripts.

TECHNICAL CONTROLS
38 / 50 PASSED
10/12 DORA CONTROLS EVIDENCED
Technical Evidence Scope: This assessment audits technical controls visible in device configuration dumps and does not constitute a formal organizational compliance certification.
Evaluated Controls 50 Checks
Compliant Items 38 Checks
Critical Deviations 2 Items
Hardening Warnings 10 Items
Remediation Status 100% Staged
LIVE REMEDIATION & HARDENING CLI 12 Fixes Staged for Deployment
✓ Projected Score After Remediation: 100% (Fully Compliant)

          
13 · Stage 05 · Traceable Root-Cause Evidence & Forensics Suite

Automated root-cause incident autopsy & regulatory evidence dossier.

24 heuristic diagnostic engines excavate multi-file diagnostic dumps, TAC reports and configuration files to correlate causal vectors, detect memory leaks and generate auditable Pre-TAC incident dossiers under DORA Articles 17–23.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
Forensics Suite
EXEC: 9.4MS
TIER: ENTERPRISE SOC · ADMIN-ISSUED PASSES: 8 REMAINING · 3 ARCHITECTURAL RISKS DETECTED
14 · Stage 06 · Incident Command Center · Multi-Hypothesis Diagnostic Core

Evidence-Backed Incident Autopsy & Competing Hypotheses

Beyond single black-box recommendations: FerritaaS evaluates competing causal theories with mathematical confidence scores, supporting vs. contradicting proof, and generates the exact next CLI commands to isolate root cause.

CONVEYOR STANDBY · WAITING FOR STAGE 01 SANITIZATION LOCKED
ACTIVE TRIAGE INCIDENT CASE #FG-2026-0842

FortiGate-200F · Memory Pressure & SSL-VPN Packet Drop

Target: FG200F-***** · FortiOS: v7.4.2 GA (build 2571) · Status: CONSERVE MODE RISK
EVIDENCE QUALITY SCORE 74% COMPLETE

4 of 6 diagnostic signals verified. Missing cluster checksum and slab tables prevent 100% mathematical certainty.

Sanitized Configuration 15,482 lines
Memory Snapshot (top-mem) 79.8% Used
Crashlog Records 1 Crash (Signal 11)
Heuristic Checks Evaluated 24 / 24 Checks
HA Checksum Parity Missing Evidence
WAD Allocator Dump Missing Evidence
SECOND PAIR OF EYES MODE:

Test your own hypothesis against the evidence:

RANK #1
WAD Process Reverse-Proxy Memory Exhaustion
68% PROBABILITY

Explicit proxy inspection combined with heavy SSL-VPN traffic is driving WAD worker 3 to 612 MB allocation, leading to periodic conserve mode trips.

Supporting Evidence (4 facts): • Proxy mode enabled on 2GB RAM device
• MemUsed = 79.8% (>78% extreme warning)
• Crashlog contains Signal 11 WAD crash
• LogID 0100032001 conserve entry verified
Contradictory Evidence (1 fact): • Overall system CPU remains nominal (<12% usage across all cores)
RANK #2
IPS Engine Worker Pool Saturation
21% PROBABILITY
Supporting Evidence: • 8 IPS engine workers spawned
• Deep packet inspection active on Policy 3 & 4
Contradictory Evidence: • 0 IPS daemon crashes in crashlog
• Memory climb is steady linear, not packet burst
RANK #3
HA Cluster Split-Brain / Checksum Divergence
11% PROBABILITY
Supporting Evidence: • Priority weighting is 100/100 without override
Contradictory Evidence: • Heartbeat status = OK
• Session synchronization reports nominal
NEXT BEST EVIDENCE TO COLLECT Isolate Hypothesis #1 (WAD) & Rule Out #2 & #3
DIAGNOSTIC VALUE: HIGH

Run these 3 targeted commands on the FortiGate CLI to capture missing evidence and mathematically isolate the root cause:

# 1. Capture WAD worker allocation breakdown
diagnose test application wad 1000

# 2. Verify cluster-wide configuration checksum parity
diagnose sys ha checksum cluster

# 3. Dump kernel memory slab allocator
diagnose hardware sysinfo slab
Drop output into Scrubber to reach 100% confidence
15 · Enterprise Platform Capabilities Available on Higher Tier

Engineered for enterprise FortiGate operations & multi-vendor migration.

From rapid single-snapshot triage to multi-week drift analytics, continuous telemetry and third-party firewall transpilation into native FortiOS 7.4 CLI blocks.

HIGHER TIER ONLY Available on Enterprise SOC & MSP Fleet Tiers

Multi-snapshot trend analytics, continuous live telemetry probes, enterprise ITSM webhooks (ServiceNow / Jira / PagerDuty), and multi-vendor firewall transpilation require an Enterprise SOC or MSP Fleet subscription.

HIGHER TIER · ENTERPRISE SOC & MSP FLEET
ENTERPRISE

01 · Single TAC report RCA

Extract instant system health, process memory allocation, crash history and executive root-cause findings from a single diagnostic capture.

ENTERPRISE

02 · Multi-snapshot trend analytics

Correlate historical snapshots to distinguish memory leaks from normal traffic spikes, evaluate firmware upgrades and isolate silent drift.

ENTERPRISE

03 · Live incident watch

Customer-scheduled, read-only telemetry probes with automated circuit breakers to capture transient spikes without production overhead.

ENTERPRISE

04 · Enterprise ITSM & Monitoring Webhooks

Bi-directional HMAC-SHA256 signed webhooks for ServiceNow, Jira Service Management, Slack, PagerDuty, SolarWinds NCM, and Zabbix automated alarms.

ENTERPRISE TRANSPILED

Module C: Third-Party Firewall to FortiOS Migration Transpiler

TRANSPILED TO: FORTIOS 7.4.9
Source VendorCisco ASA / SonicWall
Access-Lists Parsed142 Rules
Object Groups68 Converted
NAT Directives24 VIPs

Transpiled FortiOS 7.4 Native CLI Configuration Blocks:

/* --- TRANSPILED FROM CISCO ASA 9.18 / SONICWALL TO FORTIOS 7.4 --- */ config firewall address edit "OBJ_INSIDE_DMZ_NET" set subnet 192.168.50.0 255.255.255.0 next edit "HOST_BACKUP_SERVER" set subnet 10.100.1.50 255.255.255.255 next end config firewall addrgrp edit "GRP_TRUSTED_ADMINS" set member "HOST_BACKUP_SERVER" "OBJ_INSIDE_DMZ_NET" next end config firewall policy edit 101 set name "ASA_OUTBOUND_PERMIT_HTTPS" set srcintf "port1" set dstintf "wan1" set srcaddr "GRP_TRUSTED_ADMINS" set dstaddr "all" set action accept set schedule "always" set service "HTTPS" "SSH" set nat enable next end
16 · Next step

See Ferrite in action.

Start with the local config scrubber or continue into the full incident workflow.

Try the scrubber →
PIPELINE HUD
01 Air-Gap Scrub
READY
02A HA Cluster
STANDBY
02B Change Verifier
STANDBY
03 Policy Optimizer
STANDBY
04 CIS / DORA
STANDBY
05 Forensics
STANDBY