Skip to main content
AEK
SuperUser
SuperUser
November 20, 2023
Question

Globally disable traffic log for specific service

  • November 20, 2023
  • 1 reply
  • 1178 views

Hello

We want to globally disable traffic log for specific service (e.g. DNS), not at policy level.

Anyone nows if we can do that on FortiGate?

1 reply

pminarik
Staff
Staff
November 20, 2023

"Log-level" (no / utm-only / always) of traffic sessions is an attribute of firewall policies, it cannot be configured anywhere else. If you require to not log specific traffic, you will need to create specific policies for it with logging expicitly disabled.

 

The only exception to this would be when using Security Fabric, which mandates enabled traffic logging in all policies.