IPsec tunnels Logs Not Consistently Forwarded to FortiSIEM
Â
Hi,
I want to create a correlation rule in FORTISIEM that detects when a VPN tunnel goes down and is not followed by a corresponding tunnel-up event within a defined time window.
Â
I have a FortiGate acting as a dial-up IPsec VPN hub for remote devices with forticlient(with auto reconnect) to be always connected 24/7.
some peers generate tunnel-up events that successfully reach FortiSIEM, while other peers generate tunnel-up events locally on the FortiGate but those events never appear in FortiSIEM even though the tunnel is successfully re-established.
Tunnel-down events are received consistently.
Logging level is configured to "All" and I can see tunnel-up/tunnel-down events locally on the FortiGate.
Â
Has anyone experienced forwarding of IPsec tunnel-up events or know of any FortiGate logging behavior that could explain this?
Thanks.
