I've been configuring our FAZ device on 5.2 and I can't get the source country to show up. Traffic log shows flags on destination IP, detects destination country, but doesn't do it for source IP or source country. This happens whether I import logs backed up from our FAZ 4.3 or a device reports directly to the FAZ 5.2. Our FAZ 4.3 shows source country fine from the same device reporting to it. To be clear, I configured a single device with 2 FAZ destinations (via CLI). FAZ 4.3 shows source country. FAZ 5.2 does not. I can't seem to find a config setting that would affect this on the FAZ. Help?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I doubt anyone cares but this looks like a firmware bug in 5.2 when receiving logs from 4.3. The 4.3 field dst_country gets remapped properly by FAZ 5.2 as dstcountry, but src_country does not get mapped to srccountry. The log parser for 4.3 logs likely needs to be patched to remap src_country to srccountry.
I'm hoping this will get looked at by engineering and fixed but let's just say my hopes are very dim.
Dumb question but does your FGT ( assuming this is what we are talking about ) has the geoip database
e.g
diagnose firewall ipgeo country-list
Does it report back any srccountry?
PCNSE
NSE
StrongSwan
FortiGate devices report the source country fine, logs making it to our old unit (operating in parallel right now) have source country set, raw logs on new FortiAnalyzer device shows src_country makes it but field isn't renamed/remapped to srccountry.
I'm 99.9% sure it's a bug in the 4.3 log parser used on FAZ 5.2. It remaps the other fields fine (like dst_country to dstcountry, and status to action), it just skips over src_country and doesn't use it.
Probably is. I have always avoided mixing and matching major firmware versions (4.3 vs 5.0 vs 5.2 vs 5.4) when it comes to their logging destination. I know some drastic changes take place and it usually causes sporadic or erratic behavior.
Mike Pruett
open a ticket with FTNT support, but did the release notes say this is supported? But remember FTNT start using these words such as "but with possible interoperability issues." so beadvise ;)
Ken
PCNSE
NSE
StrongSwan
The release notes for FAZ 5.2.10 states it supports reporting from 4.3.2 and above. I understand "interoperability issues" but mapping the other fields correctly and just forgetting about mapping src_country sounds more like a bug in the parser than a technical limitation. I mean, you have the exact same functionality that works perfectly for dst_country being remapped to dstcountry and appearing properly. They just need to do the same thing for src_country too.
I'll keep pushing on the support side, hope it ends up in the devs' laps and they see that it's a quick and easy fix, maybe get it included in the next FAZ 5.2 release...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.