No logs from Intrusion Prevention after update to FortiOS 6.2.6
- December 4, 2020
- 2 replies
- 6393 views
Hello everyone
on my FortiGate 601E I stopped receiving logs from Intrusion Prevention system. On version 6.2.4 everything works fine but when I update to 6.2.5 and then to 6.2.6 no logs coming from IPS. I think that IPS not working as expected and don't detect potential vulnerabilities facing my WAN-DMZ direction exposes my servers to potentials threats. Before update I received many information about potentials attacks but now my log is almost clear. I know that IPS security profiles are correctly assigned to appropriate policies in WAN --> DMZ (D-NAT) facing direction. Can anyone help me resolve this issue or explain my why logs stopped being stored in disk and fortianalyzer?
Below is the screenshot from logs pane. As you can see before upgrade everythings works fine, many threats was detected. But now after 11 Sep, IPS event log is almost clear except single FTP.Login.Brute.Force detection.
