FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Anonymous
Not applicable
Article Id 191856

Description

 

This article describes why FortiOS uses 'Link Monitor' and 'Link-Monitor' for different scopes.

 

Scope

 

FortiGate.

Solution


The 'Link Monitor' is monitoring the status of every interface.
It is enabled by default, and it does not require any additional settings.

The log entry is 'action="interface-stat-change" status="DOWN" msg="Link monitor: Interface WAN2 was turned down' (or up).


 
 
 
 
'Link-monitor', instead, is a feature where FortiGate is a link health monitor that is used to determine the health of a single interface.
It is configured in the config system link-monitor.

When 'Link-Monitor' is failing, an event is registered in the FortiGate.
 
Link Monitor changed state from alive to die, protocol: ping.
 
 
If the 'Link-monitor' option, like 'update-static-route' is configured, this event will pop up too.
 
 
If 'Link-monitor' is used to bring other interfaces down when the link monitor fails, a 'Link Monitor' event is registered, but as a result of 'Link monitor' failure.
 
 

To verify the link monitor status when the destination is not reachable in the CLI, the status is set to dead:

 

diagnose sys link-monitor status

 
Related document: