Description
This article describes how to send logs to FortiCloud.
Scope
FortiGate.
Solution
Activate FortiCloud:
For FortiOS 7.2.x and above, go to Security Fabric -> Fabric Connector -> Logging & Analytics -> Cloud logging -> FortiGate Cloud.
Also in case of multiple ISP or SD-WAN connection source IP and interface may be required to add.
config log fortiguard setting
set status enable
set access-config enable
set ssl-min-proto-version default
set source-ip 0.0.0.0 [it should be one of the WAN interface IP]
set interface-select-method auto [auto|sdwan|specify] <- With 'specify', it is necessary to add 'set interface WAN_INTERFAC_PORT_Number'
set upload-option realtime
set priority default
set max-log-rate 0
set enc-algorithm high
set conn-timeout 10
end
Note:
If there is an upstream firewall, the following ports need to be allowed for the FortiGate Cloud connection to work properly.
Refer to
Related article:
Troubleshooting Tip: FortiGate not sending logs to FortiCloud
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.