Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sambhu
New Contributor III

FAZ for the SDWAN -IPSec down monitor

Hi,

 

 I’m trying to use FortiAnalyzer (FAZ) to monitor IPsec tunnel down events in a large-scale SD-WAN.

Event Handlers are in place and SMTP email alerts are configured, but I’m seeing:

  1. IPsec down events don’t always generate alerts.

  2. FAZ is at HQ. When the branch-to-HQ IPsec tunnel drops, FAZ doesn’t trigger the down alert. I usually get a “down + up” alert only after the tunnel comes back up, which isn’t useful.

If this isn’t a valid use case for FAZ, what’s the recommended way to achieve timely alerts? Can FAZ generate a “device disconnected” or “device down” event when a FortiGate loses connectivity to FAZ? That would be more meaningful once the tunnels drop.

1 Solution
PhiPhan
New Contributor II

You need to check the log of FAZ and create a event from it, not the log from ADOM.

View solution in original post

10 REPLIES 10
PhiPhan
New Contributor II

In that case, you can configure the FAZ alert if not recieve log from FG after x minutes.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Creating-alerts-when-FortiAnalyzer-sto...

Sambhu
New Contributor III

Still, it's not generating events correctly- Our FAZ version is 7.4. Are there any other options?

PhiPhan
New Contributor II

What do you mean by not generating event correctly? It match your situation when FG loses connection to FAZ via VPN connection, it also avoids false alert if tunnel up/down continuously.

Sambhu
New Contributor III

There is an event being generated in FAZ > System Settings > Event Log, but the event handler is not generating any alerts with the above KB configuration.

The Event Handler is configured with desc=="Device offline" in the Generic Text Filter. This may be because the options are not the same in version 7.4. In this version, there is only Log Filter by Text, located inside the Rules section, not in the main Event Handler settings.

PhiPhan
New Contributor II

I also using 7.4 FAZ, it work until now. You need to check at the first step that FAZ generate the log with "Did not receive any log from device XXX in past X minutes"

Sambhu
New Contributor III

Still not getting the event triggered.  I have the ADOM enabled in the FAZ, and where I am trying this event handler is not the root ADOM.

PhiPhan
New Contributor II

You need to check the log of FAZ and create a event from it, not the log from ADOM.

Anthony_E
Community Manager
Community Manager

Hi,

 

I moved this post to the support forum.

 

Regards,

Anthony-Fortinet Community Team.
jgillies01
Staff
Staff

Hi Sambhu,

 

Can you confirm this request is closed, or do you still need some assistance?

 

Thank you in advance

Joanne

Joanne Gillies
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors