FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kwcheng__FTNT
Article Id 368670
Description This article describes the typical circumstances behind the 'Interface status changed'.
Scope FortiGate.
Solution

This event ID can have two different outputs which separately describe whether the interface went up or down.

 

The sample system event message(s) will be looked like below:

 

date=2025-01-07 time=09:37:32 devid="FGXXX" devname="test" eventtime=1681749451673935660 tz="-0700" logid="0100020099" type="event" subtype="system" level="warning" vd="root" logdesc="Interface status changed" action="interface-stat-change" status="UP" msg="Link monitor: Interface wan1 was turned up"

 

date=2025-01-07 time=09:37:42 devid="FGXXX" devname="test" eventtime=1681749451673935660 tz="-0700" logid="0100020099" type="event" subtype="system" level="warning" vd="root" logdesc="Interface status changed" action="interface-stat-change" status="DOWN" msg="Link monitor: Interface wan1 was turned down"

 

Monitoring interface up/down events is essential for maintaining a stable and reliable network infrastructure. Hence refer to the following link if automated stitch is required:

 

Technical Tip: Automation stitch test related to event log

 

The automated stitch can allow a set of actions to be taken immediately when this event is detected which empowers network administrators to optimize network operations and troubleshoot the root cause of the interface change event.