Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tellu
New Contributor

Can address objects be linked to IPs in logs?

I've created a bunch of address objects for all the host IPs in a given environment but in the forward traffic logs I still see IPs and some DNS entries if RDNS for those IPs has been setup (externally). I was wondering if theres a way to link these address objects in some way so its easier to read through forward traffic logs, and fortiview for identifying systems in various tables?

Also wanted to ask, is there any advantage to linking an address object to an interface? I tried to do it after the fact, but wouldn't let me as it said the object was already in use. I find it pretty frustrating that certain config changes cant be made without undoing everything related first. I dont care if it's impacting, just let me do the thing and warn me that certain policies will need to be repaired/updated.

2 REPLIES 2
sjoshi
Staff
Staff

To make it easier to identify systems in forward traffic logs and FortiView, you can use tags to link address objects. Tags allow you to group related address objects for better visibility. Regarding linking an address object to an interface, it's not possible to do it after the object is already in use due to potential impacts on existing configurations. It's recommended to plan such changes beforehand to avoid disruptions and ensure smooth operations.

Let us know if this helps.
Salon Raj Joshi
dingjerry_FTNT

Hi @tellu ,

 

The simple and quick answer is NO.

 

However, since you can get the IP and policy ID in the log, you can go back to the firewall policy settings to check whether this IP is linked to one address object manually.

Regards,

Jerry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors