Technical Tip: Enable the external syslog in a FortiMail-Cloud instance
| Description | This article describes how to configure and enable an external syslog in a FortiMail-Cloud instance. |
| Scope | FortiMail Cloud. |
| Solution | To configure an external/remote syslog or something similar in a FortiMail Cloud (FML-CLD) instance, an admin account with the 'superadmin' is necessary. This profile is for the exclusive use of FortiMail Cloud administrators.
If FortiMail needs to send logs to an external syslog, follow these steps:
(*) If the external syslog uses TCP over TLS, verify the following:
Limitations:
FortiMail-Cloud uses different IP addresses for non-mail traffic, like RADIUS, syslog, or LDAP. If the instance is of the legacy type (*.fortimail.com), the source IP address for all traffic is the same as the instance's own address. Instead, if the instance belongs to the new platform (*.fortimailcloud.com), the IP addresses from which this traffic originates reside within the same subnet where the instance is hosted. For example, if the instance name is domain-com.fortimailcloud.com, it resolves to the following IP addresses: In the Syslog server and/or perimeter firewall, the traffic from the following subnets should be allowed: It is possible to restrict the traffic to the specific requested port only (i.e., UDP/514). |
