Question
Traffic logs/Bandwidth usage - dont trust them
We made this test: 1) all policy Logging Options - Log all Sessions 2) setup two syslogd server 3) activated forticloud 4) from Internet computer executed FTP get versus a FTP server in our internal LAN (configured using VIP NAT) behind fortigate 60D v5.0,build0252 (GA Patch 5). Transferred one file size 670.347.264 byte in about 50 minutes. logs in Fortigate memory and in syslogd related to these traffic are only 6 and total fields sentbyte, rcvdbyte are less then 500.000. The same in Forticloud where first top traffic of the day is another host with 6Mb in/out. There is NO log or report about the 600Mb traffic passed thrugh the Fortigate. We open a ticket to TAC Fortinet and their reply is : " There is nothing wrong with what you observed. The session is defined by when it was initiated and when it was over, it does not give you the information what exactly you have been doing - uploading/downloading and how big was the file you transferred/downloaded. " . These means (for me) that you cant know the Bandwidth usage. All traffic related report you could get from Fortigate or Forticloud or other you may build on logs are quite incorrect. Regards
