- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate logging Issues
I am using a fortigate 3810A with firmware 5.2.5. i am trying to send logs to syslog and fortianalyzer. But when i use the managment IP as the source-ip it gives me errors.
NG-IKY-FGT3810A-01 (setting) # set source-ip 10.206.1.19
10.206.1.19 is not valid source ip.
node_check_object fail! for source-ip 10.206.1.19
value parse error before '10.206.1.19'
Command fail. Return code -8
config log syslogd setting
set status enable
set server "10.206.2.44"
set reliable disable
set port 514
set csv enable
set facility local0
set source-ip 0.0.0.0
end
please can anyone help with this.
Solved! Go to Solution.
- Labels:
-
Analytics & Reporting
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
[cid:] Mamoon Ansar
Sr. Systems Engineer - Major Accounts
Mobile: +1.513.703.3735
[cid:storage_emulated_0_Download_image005]
-------- Original message --------
From: "Irabor Akonoman via cent.mgt.rpt.pub"
Date: 3/1/2016 04:50 (GMT-05:00)
To: cent.mgt.rpt.pub@fuse-lists.fortinet.com
Subject: [cent.mgt.rpt.pub] - Fortigate logging Issues
I am using a fortigate 3810A with firmware 5.2.5. i am trying to send logs to syslog and fortianalyzer. But when i use the managment IP it gives me errors.
NG-IKY-FGT3810A-01 (setting) # set source-ip 10.206.1.19
10.206.1.19 is not valid source ip.
node_check_object fail! for source-ip 10.206.1.19
value parse error before '10.206.1.19'
Command fail. Return code -8
please can anyone help with this.
-----End Original Message-----
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
[cid:] Mamoon Ansar
Sr. Systems Engineer - Major Accounts
Mobile: +1.513.703.3735
[cid:storage_emulated_0_Download_image005]
-------- Original message --------
From: "Irabor Akonoman via cent.mgt.rpt.pub"
Date: 3/1/2016 04:50 (GMT-05:00)
To: cent.mgt.rpt.pub@fuse-lists.fortinet.com
Subject: [cent.mgt.rpt.pub] - Fortigate logging Issues
I am using a fortigate 3810A with firmware 5.2.5. i am trying to send logs to syslog and fortianalyzer. But when i use the managment IP it gives me errors.
NG-IKY-FGT3810A-01 (setting) # set source-ip 10.206.1.19
10.206.1.19 is not valid source ip.
node_check_object fail! for source-ip 10.206.1.19
value parse error before '10.206.1.19'
Command fail. Return code -8
please can anyone help with this.
-----End Original Message-----
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you so much Mamoon, the fortigate is an ISP firewall and there are a lot of vdoms on it.
Some sampling is shown below:
NG-IKY-FGT3810A-01 (vdom) # edit
BBA_UTM_PRI
BBA_UTM_PUB
CAMAC
CommVault
EFCP
Guest_WLAN
HONGDIAN_M2
HOUSE_TARA
MERAKI-POC
MOBAN
OfficeLAN
PALSHIPINNE
I was able to do syslog logging through the VDOM, but i want to enable it globally to a single fortianalyzer and syslog
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
[cid:] Mamoon Ansar
Sr. Systems Engineer - Major Accounts
Mobile: +1.513.703.3735
[cid:storage_emulated_0_Download_image005]
-------- Original message --------
From: "Irabor Akonoman via cent.mgt.rpt.pub"
Date: 3/1/2016 10:44 (GMT-05:00)
To: cent.mgt.rpt.pub@fuse-lists.fortinet.com
Subject: [cent.mgt.rpt.pub] - RE: Fortigate logging Issues
Thank you so much Mamoon, the fortigate is an ISP firewall and there are a lot of vdoms on it.
Some sampling is shown below:
NG-IKY-FGT3810A-01 (vdom) # edit
Virtual Domain Name
BBA_UTM_PRI
BBA_UTM_PUB
CAMAC
CommVault
EFCP
Guest_WLAN
HONGDIAN_M2
HOUSE_TARA
MERAKI-POC
MOBAN
OfficeLAN
PALSHIPINNE
I was able to do syslog logging through the VDOM, but i want to enable it globally to a single fortianalyzer and syslog
-----End Original Message-----
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just checked again, the ip address is associated with the root vdom and not any other vdom and it is manually assigned.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
[cid:] Mamoon Ansar
Sr. Systems Engineer - Major Accounts
Mobile: +1.513.703.3735
[cid:storage_emulated_0_Download_image005]
-------- Original message --------
From: "Irabor Akonoman via cent.mgt.rpt.pub"
Date: 3/1/2016 11:04 (GMT-05:00)
To: cent.mgt.rpt.pub@fuse-lists.fortinet.com
Subject: [cent.mgt.rpt.pub] - RE: Fortigate logging Issues
I just checked again, the ip address is associated with the root vdom and not any other vdom and it is manually assigned.
-----End Original Message-----
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Mamoon for your help.
I was able to use the source-ip 'managment ip' for the root vdom, but i am able to see the root vdom on the fortianalyzer and also another vdom, i cant see the remaining vdoms on the fortigate. Also testing connectivity to the FAZ from fortigate still shows unable to retrieve faz status
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have FAZ settings enabled in the Global VDOM?
Mamoon Ansar
Sr. Systems Engineer, Central Region
[Fortinet]
________________________________
E: mansar@fortinet.com<mailto:mansar@fortinet.com>
M: +1 513.703.3735
Skype: mansar3
899 Kifer Road | Sunnyvale, CA 94086
________________________________
www.fortinet.com<http://www.fortinet.com> [Twitter] <http://www.twitter.com/fortinet> [LinkedIn] <http://www.linkedin.com/company/fortinet> [Facebook] <http://www.facebook.com/fortinet> [YouTube] <http://www.youtube.com/user/SecureNetworks> [Google+] <https://plus.google.com/+fortinet>
From: "Irabor Akonoman via cent.mgt.rpt.pub"
Reply-To: "cent.mgt.rpt.pub@fuse-lists.fortinet.com<mailto:cent.mgt.rpt.pub@fuse-lists.fortinet.com>"
Date: Thursday, March 3, 2016 at 9:07 AM
To: "cent.mgt.rpt.pub@fuse-lists.fortinet.com<mailto:cent.mgt.rpt.pub@fuse-lists.fortinet.com>"
Subject: [cent.mgt.rpt.pub] - RE: Fortigate logging Issues
Resent-From:
Resent-Date: Thursday, March 3, 2016 at 9:07 AM
Thanks Mamoon for your help.
I was able to use the source-ip 'managment ip' for the root vdom, but i am able to see the root vdom on the fortianalyzer and also another vdom, i cant see the remaining vdoms on the fortigate. Also testing connectivity to the FAZ from fortigate still shows unable to retrieve faz status
-----End Original Message-----
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes still enabled in global vdom.
