Created on
04-20-2015
02:42 AM
Edited on
06-19-2025
12:59 AM
By
Jean-Philippe_P
Description
Scope
Solution
Additional Note:
The mentioned command in this article (set loglocaldeny enable) is no longer available on the newer versions of FortiOS.
On later versions, including v7.2.x and v7.4.x, the command to use would be:
Fortigate # config log setting
(setting)# set fwpolicy-implicit-log enable
(setting)# end
Another way to do this would be to create a Deny Policy and enable the option 'Log Violation Traffic', as seen on the screenshot below:
The GUI view for logging the local-in denied traffic will be as follows, to log the denied traffic:
And on CLI, it would be the same as the previous versions:
Fortigate # config log setting
(setting)# set local-in-deny-unicast enable
(setting)# set local-in-deny-broadcast enable
Related article:
Technical Tip: How to configure the logging of Denied Traffic to a FortiGate interface
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.