Skip to main content
Contributor III
February 4, 2009
Question

Logging Denied Traffic

  • February 4, 2009
  • 4 replies
  • 6933 views
I use a fortigate 200a and am running MR7. We also use the fortianalyser for the firewall logs. I want to find out if we are able to see logs for traffic which is being denied. I know for every policy you can set an option to log all allow traffic, but if you wanted to see traffic which is being denied for a policy are you able to see this in the logs, or does anything need to be configured to see denied traffic.

    4 replies

    p768
    New Member
    February 4, 2009
    you need an explict DENY policy that you configure with Logging
    Contributor III
    February 4, 2009
    Where can you set this explict deny on the fortigate.
    red_adair
    New Member
    February 4, 2009
    solution 1 have a final rule, action DENY and check the " log violation traffic" checkbox. solution 2 All Traffic that is dropped because of implicit drop (no rule match) or violation of a state can also be logged. # conf log [syslog||fortianalyzer] filter (filter) # set other-traffic enab -R.
    daveywavey
    New Member
    February 5, 2009
    You can also take a look at this http://kc.forticare.com/default.asp?id=1819&Lang=1&SID= This way you can run a report on denied sources and you will see the hits from the above link. config system global set loglocaldeny enable end Davey
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!