Multi-location multi-subnet syslog back to central FortiAnalyzer
Hi all,
Our FortiAnalyzer at our main office gets logs and syslogs from both the main office and by IPsec VPN from a second location, which has its own FortiGate. We're also sending syslogs to a secondary syslog server at the main office location. Logs and syslogs may also come from a remote travelling office setup (IPsec from portable firewall and AP), and from dialup SSL VPN FortiClient users.
To collect more syslog data from two additional distinct subnets (old/insecure devices) at our second location I just added two separate phase 2's back to the FAZ at the main office. Then I decided that was silly, especially since there's at least one more subnet that needs to send syslog data over the VPN tunnel.
Suggestions on a better way to do this, taking into account that I can't merge the subnets or have an all-encompassing phase-2?
My thoughts were:
[ul]Any pointers appreciated.
