Skip to main content
smkml
Staff
Staff
November 14, 2022

Technical Tip: How to Integrate FortiAuthenticator in FortiAnalyzer

  • November 14, 2022
  • 0 replies
  • 3836 views
Description

 

This article describes how to integrate FortiAuthenticator to see logs in FortiAnalyzer .

 

Scope

 

FortiAuthenticator and FortiAnalyzer.

 

Solution

 

Check if the version and FortiAuthenticator model are supported in these related documents:

FortiAuthenticator

FortiAuthenticator models

 

Make sure there is no connectivity issue between both, and that port UDP 514 is open if there is a device in between:

Incoming ports

 

Set the IP of FortiAnalyzer/FortiManager in Log Settings:

 

smkml_0-1668372077462.png

 

The IP Address field also fqdn.

 

In case a fqdn is configured, it is necessary to verify that the DNS configured for the FortiAuthenticator can resolve that FQDN.

 

How to change the DNS configuration: System -> Network -> DNS.

 

Authorized the device in FortiAnalyzer, and select FortiAuthenticator ADOM (need to enable ADOM).

 

smkml_0-1668401624684.png

smkml_3-1668401760751.png

 

smkml_0-1668402161393.png

 

FortiAuthenticator only generates Event type logs and will send them to FortiAnalyzer the same.