Skip to main content
MBruck
New Member
March 23, 2007
Question

Not sending SYSLOG traffic

  • March 23, 2007
  • 9 replies
  • 5657 views
I' ve got a good one here... In the log config I defined syslog output to be sent to our syslog collection server at a specific IP address. When we didn' t receive any syslog traffic at the collection server I went to the FortiGate box and filtered connections with a destination port of 514. Well, the FortiGate box is sending syslog traffic, but not to the syslog collection server I defined in the syslog configuration, but some other IP I don' t even recognize...?!? Fireware: Fortigate-100 3.00,build0406,070126 Anyone have any ideas?

    9 replies

    rwpatterson
    New Member
    March 23, 2007
    FortiAnalyzer traffic also uses that port. Do you have one of those?
    MBruck
    MBruckAuthor
    New Member
    March 23, 2007
    No, this unit is not connected to a FortiAnalyzer. However, we did just figure out that the traffic is not just going to some random address. It' s actually not going out at all. The other IP we saw in the filtered connections list was actually from an internal device sending syslog out through the firewall. The address was so close we thought it was the firewall. So, with that said, are there any known issues with FortiGates not sending syslog traffic using v3.0 build 406? Thanks in advance -
    doshbass
    New Member
    March 24, 2007
    Mbruck, I hate to always do this one, but a reboot sounds like a good option Jon
    doshbass
    New Member
    March 24, 2007
    Alternatively perhaps teher is a way to kill and restart the syslog process. I do not know what the process is so can' t help, but someone on the forum might be able to help.
    Contributor III
    March 27, 2007
    try to sniff. Enter commands like: diagnose sniffer packet any ' port 514' 4 You will know if SYSLOG packets are sent from the fortigate
    MBruck
    MBruckAuthor
    New Member
    March 27, 2007
    Thanks everyone for the comments and suggestions. As it turned out the syslogd filters were not set properly and the unit simply wasn' t sending SYSLOG traffic. I' ve not noticed new FortiGate boxes coming with the filters disabled, so I wasn' t expecting that.
    mauirixxx
    New Member
    April 11, 2007
    mbruck, I just upgrade from firmware v2.80 to v3.00 build 8424,070322, and I am experiencing this right now. where exactly did you look to re-enable syslog filters? Before the update, obviously everything was working great, but to be on the safe side I backed up the config, and applied the update. Should I re-apply my backup config? I didn' t do it because all of my policies and other misc settings were saved. Thanks for the help, I' m really liking this release so far save for this syslog issue. err .. EDIT: and 2 minutes later, I realize syslog was set to ALERT, instead of INFORMATION. Ok, so NOW my question is, what would be the optimal setting? Notification, Information, Alert, Debug etc etc ?
    MBruck
    MBruckAuthor
    New Member
    April 11, 2007
    As for the log setting (i.e., info, alert, etc.) that depends on what you are trying to accomplish with the log data. I think Info if your trying to log all traffic, but alert if you only care about tracking security events. Debug is for diagnosing issues and produces a lot of data that would otherwise be a waste of disk space.
    mauirixxx
    New Member
    April 12, 2007
    thanks for the input mbruck :)
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.