Skip to main content
MitchK
New Member
March 7, 2012
Question

Logging of local broadcast packets

  • March 7, 2012
  • 3 replies
  • 6463 views
As everyone here knows, NETBIOS and other local broadcasts are denied by default in the Fortigates, and logging shows every single broadcast. How can this be stopped? I tried to create a rule allowing the broadcasts, which would then cause them not to be logged, but I couldn' t create the rule. Looking at the logs, there is a source interface, but the destination interface is either the VDOM name or " N/A" . Also, the " Service" section of the rule does not contain NETBIOS or Broadcasts or anything like that. Please don' t tell me to " try" this command or that command, I' ve seen them and tried them, they don' t work. Sorry to seem annoyed, but I am. Other brands of firewalls permit EASY construction of a rule that denies these packets and also permits non-logging of the denials. Why doesn' t Fortigate have what would seem to be a no-brainer of a feature?

    3 replies

    Greg_Hennessy
    New Member
    March 24, 2012
    Totally Agree This broadcast logging is getting very tedious. Tens of thousands of extraneous log events per hour with no obvious way of disabling generation. And like you, I have trawled the forum and tried all the suggestions. Greg
    TopJimmy
    New Member
    March 27, 2012
    there' s a tech note for it here: http://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&externalId=FD33057 If that doesn' t work in your environment, I' d open a ticket to Fortinet and ask them. Complaining here does nothing.
    mbrowndcm
    New Member
    March 30, 2012
    config log {disk | fortianalyzer | fortianalyzer2 | fortianalyzer3 |memory | syslogd | syslogd2 | syslogd3 | webtrends | fortiguard} filter extended-traffic-log {disable | enable}  
    Described to cover:
      Enable or disable ICSA compliant logs. This setting is independent from the traffic setting.  Traffic log entries include generating traffic logs:  • for all dropped ICMP packets  • for all dropped invalid IP packets (see “check-protocol-header {loose | strict}” on page 416, “anti-replay {disable | loose | strict}” on page 415, and “check-reset-range {disable | strict}” on page 417.  • for session start and on session deletion  This setting is not rate limited. A large volume of invalid packets can dramatically increase the number of log entries.  
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!