Not seeing Local Traffic logs for WAN interfaces?
Hi,
I have only a limited experience with Fortinet products so far.
I ran into a similiar problem on one of my first projects of setting up a Fortigate environment. This environment originally had Fortigate firewalls which did not have separate disks and configuring the log filters for memory did the trick then.
Now I have set up FortiWifi-61F at home and I seem to have problems seeing any logs on my WAN interfaces which should naturally have constant scanning traffic being blocked on them and visible on the Local Traffic logs?
My WAN1 interface is acting as a DHCP Client and connected to a 5G device that is in bridged mode
My WAN2 interface is acting as a DHCP Client and connected to a 4G device that is in bridged mode
I have made a third separate WAN interface as VLAN interface which is connected through a Fortilink to a Fortiswitch and in one of its access ports it has an ADSL router in bridged mode.
5G is currently active as it has the best route.
I was originally running a 6.4 software but upgraded to 7.2. last night
So far I have done the following things (some of the things are on by default i guess)
config log disk setting
set status enable
end
config log disk filter
set severity information
set forward-traffic enable
set local-traffic enable
set multicast-traffic enable
set sniffer-traffic enable
set ztna-traffic enable
set anomaly enable
set voip enable
set dlp-archive enable
end
config log setting
set fwpolicy-implicit-log enable
set local-in-deny-unicast enable
set local-in-deny-broadcast enable
set local-out disable
end
But even after this I am not seeing really any Local Traffic logs related to the WAN interfaces.
One problem also seems to be that in my FIrewall Policy section, the Implicit Deny rule has only logged 314B worth of traffic. I guess it must only handle traffic going through the firewall and now since there is no Static NAT type configurations at the moment its not logging any denied traffic?
I would really like to see and log even the scanning traffic coming from the Internet and I am wondering what I need to do to get it visible