FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
vraev
Staff
Staff
Article Id 247659
Description

 

This article describes how to establish FGFM tunnel from FortiAnalyzer to FortiCloud, in order to remotely access FortiAnalyzer via the FortiCloud web interface.

 

Scope

 

FortiAnalyzer 7.2 or above.

 

Solution

 

The region that will be used to connect to the FortiGate Cloud can be found under the FortiGate Cloud -> Account Setting.

 

vraev_4-1688024334367.png

 

 

FortiAnalyzer configuration:

 

execute cloud-remote-access login <Account id> <password> <domain> <email confirm>




config system central-management
    set type fortigatecloud
end

 

Update: Under the FortiAnalyzer 7.2.2 the option is changed to the following format:

config system central-management
    set type cloud-management

end

Troubleshooting commands:

diagnose debug application forticldd  255

diagnose test application forticldd 

curtime : sec=1677502545
Forticldd Diag Test Usage:

1: Daemon info (PID, meminfo, backtrace ...)
2: switch on/off debug messages
3: dump Contract Controller status
4: Update contract controller
5: Show fgfm status
6: Recover fgfm
99: restart forticldd

diagnose fmnetwork interface list

diagnose system admin-session list

Example:

Vito_1-1677661455450.png

 

Vito_2-1677661455451.png

 

Vito_3-1677661455453.png

 

Vito_4-1677661455455.png

 

From FortiGate Cloud:

'Services' -> 'Asset Management' -> 'Products' -> 'Product List' -> 'your FortiAnalyzer SN number' -> 'Remote Access' icon. This is the only operation that is supported.

 

Note that the FortiAnalyzer device needs to be registered with FortiCare under the same account to show up under the 'Asset Management' portal.

 

vraev_3-1688024096225.png

 

 

 

Vito_6-1677661536129.png

Related documents:

Docs: cloud-remote-access

Docs: Enabling remote access from FortiCloud