Skip to main content
mkannan
Staff
Staff
February 20, 2017

Technical Tip: How to connect a FortiWeb to a FortiAnalyzer

  • February 20, 2017
  • 0 replies
  • 11007 views

Description

 

This article describes how to connect FortiWeb to a FortiAnalyzer Device or VM.


Scope

FortiWeb and FortiAnalyzer.

Solution:

On the FortiWeb: 

  1. Configure FortiWeb with the FortiAnalyzer IP.

  • Go to Log & Report -> Log Policy -> FortiAnalyzer Policy.

  • Create a new policy.

    • Set Name.

    • Set FortiAnalyzer IP.

    • Select 'OK'.


84.png

 

  • Use the FortiWeb CLI:


config log fortianalyzer-policy
    edit "0"
        set ip-address <FortiAnalyzer-IP>
    next
end

 

  1. Configure FortiAnalyzer Log Settings.

  • Go to Log & Report -> Log Config -> Global Log Settings.

  • Enable the FortiAnalyzer [Checkbox].

  • Specify 'Log Level' as 'Information'.

    • Specify 'FAZ' as the 'FortiAnalyzer Policy' (the name of the FortiAnalyzer policy created in the previous step).

    • Select 'Apply'.

85.png

 

  • Using CLI:

 

config log forti-analyzer
    set severity debug
    set fortianalyzer-policy 0
end

 
On the FortiAnalyzer.

The FortiWeb can be added either to a Fabric ADOM or a dedicated FortiWeb ADOM (recommended).

 

  1. ADOM configuration.

  • Enable the ADOM.

mkannan_FD40249_tn_FD40249-3.jpg


  1. Device registration.

  • Go to Root-ADOM -> Device Manager -> Unregistered device.


mkannan_FD40249_tn_FD40249-4.jpg

 

  • After selecting 'OK', the device will be added, verified, and 'CLOSE' will be selected.


mkannan_FD40249_tn_FD40249-5.jpg


  • Log in to the FortiWeb ADOM:


mkannan_FD40249_tn_FD40249-6.jpg



There is another option to integrate FortiWeb with FortiAnalyzer.

 

  1. Creating New ADOM.

  • Go to System Settings -> ADOMs -> Create New.

  • Set Name.

  • Select Type: FortiWeb.

  • Keep all other settings with Default Values.

  • Select 'OK'.


86.png

 

  1. Change to the New FortiWeb ADOM to integrate FortiWeb.

  • Go to Dashboard -> Select the ADOM Button. 


88.png


  • Select the New FortiWeb ADOM created.


89.png

 

  1. Configure FortiWeb in FortiAnalyzer -> Device Manager.

  • Go to Device Manager.

  • Select Add Device.


90.png

 

  • Set Name.

  • Select Link Device by Serial Number.

  • Set the FortiWeb Serial Number.

  • Select the FortiWeb Device Model.

  • Select 'Next'.


91.png

 

  • A New Database is created, and FortiWeb will be integrated.

  • Select 'Next' to finish.

 

92.png

 

  • It is possible to see the wrong Version and Model: it is normal, and FortiAnalyzer and FortiWeb need to complete the synchronization.


93.png

 

  • Complete the configuration on FortiWeb, then after a few seconds, FortiWeb will connect to FortiAnalyzer and the correct information will become visible.


94.png


  • If the FortiWeb status appears as 'Down' in FortiAnalyzer (especially with FortiAnalyzer v7.4.8+), legacy authentication mode needs to be enabled:


FortiAnalyzer CLI:

config system log settings
    set legacy-auth-mode enable
end

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.