Skip to main content
adavila
Staff & Editor
Staff & Editor
September 24, 2025

Technical Tip: Enable the external syslog in a FortiMail-Cloud instance

  • September 24, 2025
  • 0 replies
  • 908 views
Description

This article describes how to configure and enable an external syslog in a FortiMail-Cloud instance.

Scope

FortiMail Cloud.

Solution

To configure an external/remote syslog or something similar in a FortiMail Cloud (FML-CLD) instance, an admin account with the 'superadmin' is necessary. This profile is for the exclusive use of FortiMail Cloud administrators.

 

If FortiMail needs to send logs to an external syslog, follow these steps:

  1. Create a ticket in the Technical Assistance Center indicating the following:
  • The name of the FortiMail Cloud instance.
  • Syslog external/external server IP address or the URL that can be reached from the Internet.
  • The port that is used by the syslog external/remote server, and whether it is TCP or UDP. If the external syslog is using TCP over TLS, provide the certificate (*) and both the key file and password.

  1. Once the ticket is created, a TAC engineer will send a confirmation message to inform that the syslog server was configured.

  2. The FortiMail Cloud allows any syslog server, including FortiSIEM or FortiAnalyzer, to work as a syslog server.

(*) If the external syslog uses TCP over TLS, verify the following:

  • The certificate must be signed by a valid CA (trusted).
  • If the certificate is signed by an invalid (untrusted) CA, the certificate must be auto-signed.

 

Limitations:

  • FortiMail-Cloud instances do not allow the installation of external agents such as Splunk or other syslog servers, which use collection agents.
  • The only solution is to configure syslog as described above.

 

FortiMail-Cloud uses different IP addresses for non-mail traffic, like RADIUS, syslog, or LDAP.

If the instance is of the legacy type (*.fortimail.com), the source IP address for all traffic is the same as the instance's own address. Instead, if the instance belongs to the new platform (*.fortimailcloud.com), the IP addresses from which this traffic originates reside within the same subnet where the instance is hosted. For example, if the instance name is domain-com.fortimailcloud.com, it resolves to the following IP addresses:
159.48.178.131.
148.230.56.132.

In the Syslog server and/or perimeter firewall, the traffic from the following subnets should be allowed:
159.48.178.0/24.
148.230.56.0/24.

It is possible to restrict the traffic to the specific requested port only (i.e., UDP/514).
If specific IP addresses are required for each type of traffic, consult with Fortinet TAC to obtain this information.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.