Description | This article describes the impacts on the Security Fabric Topology when 'set configuration-sync' is set to local. |
Scope | FortiGate, FortiAnalyzer, FortiManager. |
Solution |
In a network topology with a centralized FortiGate (root FortiGate) and downstream FortiGates (all devices are managed by FortiManager), a logging icon showing all is by design when Security Fabric is enabled.
If needed to centralize logging management through FortiManager , there is a setting to achieve it:
config system csf set configuration-sync local end
Below are the impacts on Security Fabric devices, when "set configuration-sync local" is configured on the downstream device :
On the downstream FortiGate:
On the FortiAnalyzer, the connection is UP and the logs are stored:
On the FortiManager device, the device is UP and still can be managed by FortiManager:
|
Contributors