Skip to main content
JaapHoetmer
New Member
August 24, 2016
Question

FG not sending logs to FAZ

  • August 24, 2016
  • 7 replies
  • 32235 views

Hi there

I have several FGs already sending logs to a FAZ, over ipsec connections, but I am having issues adding a new FW.

The logging is configured using the correct source-ip address, I have successfully checked sending pings from the FG to the FAZ using the source-ip option, and diag sniffer shows the flow of packets, albeit with RSTs in the flow. The FG definition is added to the FAZ, still, the FG reports it can't communicate with the FAZ.

 

config log fortianalyzer setting set status enable set source-ip 192.168.24.1 set server 192.168.40.15 set reliable enable end

MIN-FW-001 # exec log fortianalyzer test-connectivity Failed to get FAZ's status.

The sniffer flow from the test-connectivity command:

MIN-FW-001 # diag sniffer packet any "host 192.168.40.15" 4 interfaces=[any] filters=[host 192.168.40.15] 1303.708288 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: syn 4266655446 1303.724212 ipsec_CT in 192.168.40.15.514 -> 192.168.24.1.1364: syn 1201754132 ack 4266655447 1303.724493 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: ack 1201754133 1303.726584 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: psh 4266655447 ack 1201754133 1303.742509 ipsec_CT in 192.168.40.15.514 -> 192.168.24.1.1364: ack 4266655740 1303.745975 ipsec_CT in 192.168.40.15.514 -> 192.168.24.1.1364: psh 1201756905 ack 4266655740 1303.746874 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: ack 1201754133 1313.722355 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: fin 4266655740 ack 1201754133 1313.738176 ipsec_CT in 192.168.40.15.514 -> 192.168.24.1.1364: fin 1201756914 ack 4266655741 1313.738539 ipsec_CT out 192.168.24.1.1364 -> 192.168.40.15.514: rst 4266655741

 

Any ideas? Why the RST packets?

As the RST breaks the session, diag debug flow shows 'no session matched' messages after the RSTs appear.

 

Thanks

 

    7 replies

    emnoc
    New Member
    August 24, 2016

     

    Things to check

     

    1: Are you going out the right interface ( check  route, route-table )

     

    2: Any FAZ limits or capacity ( review systems logs )

     

    3: can you reboot the FAZ

     

    4: can you run a packet capture on  at the FAZ

     

     

    JaapHoetmer
    New Member
    August 24, 2016

    Thanks for the help emnoc.

     

    [ol]
  • Routing seems to be ok, as indicated by the handshake and exchange in the sniffer trace above, and as per routing table.
  • Checked for FAZ limits, no problem there.
  • Tried to reboot the FAZ to no avail, as the problem persists after the reboot.
  • I'll try that packet capture on the FAZ. I'll also run a sniffer trace on the peer firewall.[/ol]

    Thanks

     

  • MrSinners
    New Member
    August 25, 2016

    You could try the following debugging on the fortigate to see if there are errors in the communication between the FG and the FAZ:

     

    # diagnose debug enable # diagnose debug application miglogd -1

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!