Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Excessive traffic on port 514 from loop back

Hi I am seeing a lot of traffic from 127.0.0.1 to 127.0.0.1 on port 514. As this port is usually syslog rec' v port, or RSH this seems rather strange. At least 100 connections most of the time. Can anyone explain? Thanks.
7 REPLIES 7
Fireshield
New Contributor

Do you somehow have itself as the syslog or FortiAnalyzer?
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT
Not applicable

No, under Log Settings, both Syslog and FortiAnalyzer are unchecked.
Not applicable

I assume you' re logging to internal memory of the FG unit, hence the traffic.
Fireshield
New Contributor

I just checked 3 of our boxes that are logging to memory and none of them have sessions like this, 2.8 or 3.0. Tried the session tables and packet sniffer.
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT
Not applicable

Yes, I am logging to the internal memory. I run Fortigate-60 3.00,build0318,060630. Still seems strange that internal logging sends syslog packets to itself.
Not applicable

Just remove logging to internal memery. You' ll see the traffic disappear. It' s not that strange though
Not applicable

By the way, it' s better to log to an external box (FortiAnalyser, or syslog server (kiwi deamon?) It will not disappear at reboot and more importantly reduce the memory load on the FG. esp. on small models. 50A & 60.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors