Skip to main content
Tutek
New Member
November 18, 2025
Question

Security Fabric and logging advice needed.

  • November 18, 2025
  • 1 reply
  • 338 views

Hello,

I would like to ask for your advice on how you would configure logging on Fortigate routers and whether it is worth enabling security fabric in such a configuration:

-one main Fortigate and Fortianalyzer in the main location.

-four Fortigate routers at the branches connected to the main Fortigate (hub and spoke topology) via doubled IPSEC (SD-WAN).

-the remote Fortigate routers do not have UTM licenses because all network traffic is reversed and goes out to the Internet through the main Fortigate router.

 

Now how would you configure the security fabric and logging in this case?

1. Security fabric disabled, logging into Fortianalyzer only from the main Fortigate (here, traffic to the Internet is visible from remote Fortigates anyway) - this is the current situation.

The downside of this solution is that in order to check local traffic, I have to log in to each of the branch  Fortigates.

2. Security fabric disabled, but adding remote Fortigates to Fortianalyzer (there will be duplicate logs here)

3. Enabling security fabric and adding remote Fortigates to Fortianalyzer?

 

Thank you.

1 reply

pete_goodridge
New Member
November 18, 2025

Hi,

 

I cannot speak to the fabric side, but I will watch for the replies.

 

We use Fortianalyzer and all of our firewalls log to it. One of the best things about this is that you an filter for the traffic you are interested in, and see where the problem occurs. Short answer: have everything log to Fortianalyzer. 

 

Regards,

Pete

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!