FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
heng
Staff
Staff
Article Id 204883
Description The article describes why there are broadcast traffic and multicast traffic seen out from the FortiAnalyzer.
Scope Specific FortiAnalyzer models came with the FortiRecorder module 
Solution

The following broadcast and multicast traffic is being sent out from the FortiAnalyzer over time as source traffic sometimes overwhelms the low link interface e.g. 100Mbps link. This traffic is for the camera discovery broadcast traffic and multicast traffic for the camera module. 

The following traffic can be seen on certain FortiAnalyzer model like FAZ-200F/FAZ-300F/FAZ-400E/FAZ-800F/FAZ-1000E/FAZ-2000E/FAZ-3000F/FAZ-3700F.  

 

255.255.255.255 port UDP/6666
255.255.255.255 port UDP/59123
234.200.200.200 port UDP/59125
239.255.255.250 port UDP/1900
239.255.255.250 port UDP/3702

 

fyheng_0-1645058757946.png

 

The module can be disabled via CLI, if it is not required for the FortiRecorder module to run, by default it is enabled. 

 

To disable the FortiRecorder module in the CLI and to stop the broadcast and multicast traffic run the following command:

 

# config system global

   set disable-module fortirecorder

 end

Contributors