Allow in FortiGate to also configure FortiAnalyzer via FQDN. This way we can make high availability via DNS or reverse proxy for example.
set server FQDN or IP Address
Regards,
Celio di Cavalcanti
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi
I suppose that this is not your case. I you where able to (for examlple) to load balance logs between to FAZ then you would come to a point that some of logs would be in 1st FAZ and the rest in 2nd FAZ where from forensics point of view is not good idea.
a. If you have 2 Fortianalyzer Devices, you can configure Fortigate to push on both devices.
except from these
b. Fortianalyzer has a function of the first Fortianalyzer to be in Analyzer Mode and another on Collector mode . That means that Analyzer pushes to Collector.
c. Another option is that if your FAZ is a VM machine you can have a second instance in suspend mode with the same IP in DR site (via Layer 2 or NAT communication).
Follows FAZ modes comparison/capabilities
--------------------------------------------
If all else fails, use the force !
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1709 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.