Skip to main content
BusinessUser
Explorer
December 26, 2023
Solved

What is the difference between logging UTM sessions and all sessions in the FW?

  • December 26, 2023
  • 1 reply
  • 17871 views

What happens if it is a "normal" firewall rule without any filtering applied?

Best answer by adimailig

Hi,

When "Log Allowed Traffic" in firewall policy is set to "Security Events" it will only log Security (UTM) events (e.g. AV, IPS, firewall web filter), providing you have applied one of them to a firewall (rule) policy.
'Log all sessions' will include traffic log include both match and non-match UTM profile defined.

Reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-Security-Events-and-All-session/ta-p/206881

If there is no Security Profile enable on firewall policy and "Log Allowed Traffic" is set to "Security Events", then there will be no log generated by firewall policy.

1 reply

adimailig
Staff & Editor
adimailigAnswer
Staff & Editor
December 26, 2023

Hi,

When "Log Allowed Traffic" in firewall policy is set to "Security Events" it will only log Security (UTM) events (e.g. AV, IPS, firewall web filter), providing you have applied one of them to a firewall (rule) policy.
'Log all sessions' will include traffic log include both match and non-match UTM profile defined.

Reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-Security-Events-and-All-session/ta-p/206881

If there is no Security Profile enable on firewall policy and "Log Allowed Traffic" is set to "Security Events", then there will be no log generated by firewall policy.