
Not applicable
Created on ‎11-22-2006 10:41 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Excessive traffic on port 514 from loop back
Hi I am seeing a lot of traffic from 127.0.0.1 to 127.0.0.1 on port 514. As this port is usually syslog rec' v port, or RSH this seems rather strange. At least 100 connections most of the time.
Can anyone explain? Thanks.
7 REPLIES 7
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you somehow have itself as the syslog or FortiAnalyzer?
FCSE > FCNSP 2.8 > FCNSP 3.0
(Former) FCT
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT

Not applicable
Created on ‎11-22-2006 11:51 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, under Log Settings, both Syslog and FortiAnalyzer are unchecked.

Not applicable
Created on ‎11-22-2006 12:15 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume you' re logging to internal memory of the FG unit, hence the traffic.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just checked 3 of our boxes that are logging to memory and none of them have sessions like this, 2.8 or 3.0. Tried the session tables and packet sniffer.
FCSE > FCNSP 2.8 > FCNSP 3.0
(Former) FCT
FCSE > FCNSP 2.8 > FCNSP 3.0 (Former) FCT

Not applicable
Created on ‎11-22-2006 01:26 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I am logging to the internal memory. I run Fortigate-60 3.00,build0318,060630.
Still seems strange that internal logging sends syslog packets to itself.

Not applicable
Created on ‎11-22-2006 02:45 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just remove logging to internal memery. You' ll see the traffic disappear.
It' s not that strange though

Not applicable
Created on ‎11-22-2006 02:47 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By the way, it' s better to log to an external box (FortiAnalyser, or syslog server (kiwi deamon?)
It will not disappear at reboot and more importantly reduce the memory load on the FG. esp. on small models. 50A & 60.
