Description
This article describes how to generate logs for matches to the implicit deny policy, as well as a more specific alternative method to capture deny logs.
Scope
FortiGate.
Solution
While verifying the functionality of an implicit deny policy or a newly configured allow policy it is sometimes necessary to view logs for traffic that was denied.
By default, FortiGate will not generate the logs for denied traffic in order to optimize logging resource usage. In some environments, enabling logging on the implicit deny policy which will generate a large volume of logs.
It is possible to enable the ‘Log IPv4 Violation Traffic’ under ‘implicit deny policy’.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.