Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

SMA 200 Appliance keeps rebooting every few minutes

SMA 200 Appliance keeps rebooting every few minutes. This is a newly setup appliance with not much on it.

The TSR dump shows this in the swMonitorMessages file. Where should we look to find the root cause of this?


Thanks


[Thu Mar 09 15:18:20 2023]swMonitor: reboot count=1

[Thu Mar 09 15:18:40 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:19:01 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:19:21 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:19:41 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:20:01 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:20:21 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:20:41 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:21:01 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:21:21 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:21:41 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:22:01 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:22:01 2023]swMonitor: check failure count (11) >= Threshold1

[Thu Mar 09 15:22:01 2023]swMonitor: httpd monitor failed with error code:1

[Thu Mar 09 15:22:01 2023]swMonitor: httpd monitor restart EasyAccess

[Thu Mar 09 15:22:38 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:22:38 2023]swMonitor: check failure count (12) >= Threshold1

[Thu Mar 09 15:22:38 2023]swMonitor: httpd monitor failed with error code:1

[Thu Mar 09 15:22:58 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:22:58 2023]swMonitor: check failure count (13) >= Threshold1

[Thu Mar 09 15:22:58 2023]swMonitor: httpd monitor failed with error code:1

[Thu Mar 09 15:23:18 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:23:18 2023]swMonitor: check failure count (14) >= Threshold1

[Thu Mar 09 15:23:18 2023]swMonitor: httpd monitor failed with error code:1

[Thu Mar 09 15:23:38 2023]swMonitor: 'httpd' process failed

[Thu Mar 09 15:23:38 2023]swMonitor: check failure count (15) >= Threshold2

[Thu Mar 09 15:23:38 2023]swMonitor: httpd monitor failed with error code:2

[Thu Mar 09 15:23:38 2023]swMonitor: httpd monitor notified watchdog

[Thu Mar 09 15:23:38 2023]swMonitor: sent SIGUSR1 to watchdog

Category: Secure Mobile Access Appliances
Reply

Answers

  • AjishlalAjishlal Community Legend ✭✭✭✭✭

    @abhishekbisaria

    Did you upload any certificate into the SMA? If you upload the certificate, unbind the certificate and try.

    NB: Before uploading the certificate make sure your SMA have the latest firmware.

  • BWCBWC Cybersecurity Overlord ✭✭✭

    @abhishekbisaria the SMA is quite old, what firmware is running on it? I had trouble with 10.2.1.6 and publishing Exchange Active Sync, no problems with 10.2.1.7 on that front.

    Is the SMA still crashing when you deny any access to it from the WAN (on your Firewall by blocking 80/443)?

    --Michael@BWC

  • Hi Michael,

    The firmware version is: 10.2.1.7-49sv

    Do you want me to try denying outgoing access from SMA to WAN?

    Thanks

    --Abhishek

  • BWCBWC Cybersecurity Overlord ✭✭✭

    Abhishek, no, because your httpd is crashing I really meant to deny any traffic from WAN to the SMA, just for a little while to see if the process is still crashing. Outbound shouldn't be a problem here.

    Does the SMA 200 has a serial console port which you could check as well? Hardware related issues might be shown here.

    --Michael@BWC

  • Hi Michael,

    All services were denied already from WAN to SMA except for TCP 8443 that is needed to connect to access the portal.

    I stopped that also and waited for about half hour. It didn't seem to make any difference, the up time was only 5 minutes when I logged in right after enabling the access.

    There is no console port on this appliance.

  • BWCBWC Cybersecurity Overlord ✭✭✭

    @abhishekbisaria I'am confused, according to the Getting Started Guide there is a serial console port on the SMA 200, not sure if anything will be reported there, but it's worth a try because it might show messages which could not be logged to file.

    If noone accesses the appliance and the appliance is still rebooting it might be hardware related. But when the httpd is crashing it looks like that there are still incoming connections.

    Do you have any special characters in your configuration, like for usernames, portal names, etc?

    On the other hand, the SMA 200 is still supported (until 2024), what does SNWL Support says about it?

    --Michael@BWC

  • Hi Michael,

    I am sorry but my expertise with this stuff is minimal. Yes, the appliance does have the console port. Though I could not find the cable and the compatible computer to connect it to.

    SonicWall support suggested to factory reset it and check if the problem exists. If so then they would conclude that it is a hardware problem.

    I was trying to avoid doing that but I don't see any other option so I am going for that now.

    Thanks a lot for your time.


    --Abhishek

  • Hi Michael,

    Just to update you. Factory resetting the appliance fixed the issue.

    Very strange, if there was a setting that was the root cause of the issue (As per the Sonicwall support) then I would expect it to not even accept that setting.


    --Abhishek

  • BWCBWC Cybersecurity Overlord ✭✭✭

    @abhishekbisaria great that you got this sorted out. If you saved a TSR before the factory reset you may compare it with a current one, if you believe you configured the system exactly like before.

    --Michael@BWC

Sign In or Register to comment.