Skip to main content
thedom
New Member
October 8, 2010
Question

issue logging udp traffic

  • October 8, 2010
  • 6 replies
  • 6204 views
Firstly: I have a faz100B Firmware Version v4.0,build0218 (MR2 Patch 2) I have a fortigate310b on latest fw too! Im having problems with the faz logging traffic(significant traffic 500gb excess) that is udp traffic on ports higher than 33000. It doesnt seem to be recording in my faz. When i log into my fortigate i can see the traffic in the sessions widget no problems there but in my faz it is not recorded. everything else seems to be logged ok. The policy in my fortgate is being set to log accepted traffic. So does anyone have any ideas or am i missing something. My issue is that most of the bandwidth we consume comes from this type of traffic not being captured so i am having a hard time with management trying to show them we need more bandwidth etc. any help would be appreciated thanks

    6 replies

    billp
    New Member
    October 8, 2010
    Is the FAZ100B fast enough to grab all the logs from a 310B generating 500GB of traffic? When I was looking at a 310B, they would not sell me a FAZ100B because it wasn' t compatible with the traffic load. I thought the 100B was set up to not accept connections from a 310B-class firewall, but never had a chance to try it. I believe the new FAZ100C appliance will work.
    thedom
    thedomAuthor
    New Member
    October 9, 2010
    Hi Bill Im not sure but the faz100b is certainly capturing everything else by the look of my reports.. anybody else have any ideas ?
    Jan_Scholten
    New Member
    October 18, 2010
    In generall the FGT only logs traffic when the session is terminated (as a log entry contains duration, and transferred bytes) which can seriously delay logging of long living sessions. Solution in this case:
    config log fortianalyzer filter   set other-traffic enable
    Which will log the start of sessions as well. But the other statments about a overwhelmed FAZ maybe true as well.
    thedom
    thedomAuthor
    New Member
    October 18, 2010
    thanks for the suggestion, i will make the change and see how we go... In regards to the faz being overwelmed what model woukld overcome this potential issue ?
    ede_pfau
    SuperUser
    SuperUser
    October 19, 2010
    We use a FAZ 400B with a A-P cluster of 310Bs. CPU usage while logging only is low (1-5%), with traffic logs active. The only drawback is the slow performance while generating reports. Some take 15-20 minutes. (Even if the only line in the final report reads " No data available." :-) If you say that you have >500 GB traffic across the FG-310B, that doesn' t relate to the performance needed for the FAZ. Depends on what you log, to what extent and how many reports you' ll create per day.
    thedom
    thedomAuthor
    New Member
    October 19, 2010
    we basically download audio/video(its legit people not pirated =) ) which we use for production, so typically in a month we would download anywhere between 500-1000gb a month. Now this application we use for the high speed content delivery(http://www.asperasoft.com/) uses udp to send data on ports above 33000. now you would think after a month i would have alot to report but unfortunately it seems like the traffic information for this application doesnt hit my faz at all. i have even created a report to show only items from the policy on my firewall which this application uses for the delivery...i suppose thats what lead me to suspect perhaps the higher udp ports do not get recorded or its a product limitation.. in terms of daily data flow for this application this would be typically around 20gb-100gb so i wouldnt think the faz should not be overwhlmed and looking at the cpu usage on the fortgiate and the faz when doing a test transfer using this software i see no signs of stress or high usage. thanks for your thoughts
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!