Skip to main content
TobiasHan
New Member
October 24, 2017
Question

FortiAnalyzer Unreachable

  • October 24, 2017
  • 1 reply
  • 13522 views

Hi,

 

i don't get a connection from the FortiGate to the FortiAnalyzer.

 

I have following architecture:

A "Test-Fortigate" with the IP 192.168.178.244. It has the FIrmware v.5.6.2 buld1486 on it.

I have "FortiAnalyzer-VM" with the IP 192.168.178.239. It has the Firmware v.5.6.0-build1557 on it.

And I have a "FortiGate HA-cluster" with IPs 192.168.178.1,  192.168.178.2, 192.168.178.3 and Firmware v.5.4.2,build1100 on it.

 

From the Test FortiGate i get a connection to FortiAnalyzer. Under settings i enable FortiAnalyzer Logging and added the IP 192.168.178.239 from the FortiAnalyzer.

On the FortiAnalyzer I get the "Unknown Device" Message and added the "Test-Fortigate". The "Test-FOrtigate" is sending data to the FortiAnalyzer. It works well.

 

But with the "FortiGate HA-Cluster" this procedure doesn't work. I don't get the "Unkown Device" Message. So I added the Device over the Device Manager manually. I toke "Add Device" and take the IP-Address 192.168.178.1 with Firmware VErsion 5.4.

When I go "next", the Device will be add, but at "Retrieving HA-Status" he is working. So I get on "Finish" and add the HA-Cluster manually. But the Logging don't work.

 

Over CLI I get a Ping from FortiAnalyzer to FortiGate HA-Cluster. And from FortiGate HA-Cluster I get a Ping to FortiAnalyzer.

 

Does anyone know this problem and can help me.

 

Thank you

 

Kind regards

Tobias

    1 reply

    TobiasHan
    TobiasHanAuthor
    New Member
    October 24, 2017

    Hi,

     

    i have added the VDOMS and i get a connection from the HA-Cluster. But Only from the Second (inactive) Cluster. There is under System Events "Connected to FortiAnalyzer 192.168.0.239" = Connect = success.

    Under the primary (active) Cluster is under system Events "Failed to connect FortiAnalyzer 10.146.0.239" -> failure -> connect failed: Connection timed out.

     

    Does anyone know, why?

     

    Thank you

     

    Kind Regards

    Tobias

    rdumitrescu
    New Member
    October 24, 2017

    Hi Tobias,

     

    The HA-Cluster have more than one vdom (root) ?

    If so, you have to check which one is the management vdom and assure that the connectivity with FortiAnalyzer is made from that vdom.

     

    Regards

    Radu

    TobiasHan
    TobiasHanAuthor
    New Member
    October 24, 2017

    Hi Radu,

     

    it works.

     

    Thank you a lot.

     

    Kind regards

    Tobias