Hi,
I’m trying to use FortiAnalyzer (FAZ) to monitor IPsec tunnel down events in a large-scale SD-WAN.
Event Handlers are in place and SMTP email alerts are configured, but I’m seeing:
IPsec down events don’t always generate alerts.
FAZ is at HQ. When the branch-to-HQ IPsec tunnel drops, FAZ doesn’t trigger the down alert. I usually get a “down + up” alert only after the tunnel comes back up, which isn’t useful.
If this isn’t a valid use case for FAZ, what’s the recommended way to achieve timely alerts? Can FAZ generate a “device disconnected” or “device down” event when a FortiGate loses connectivity to FAZ? That would be more meaningful once the tunnels drop.
Solved! Go to Solution.
You need to check the log of FAZ and create a event from it, not the log from ADOM.
Created on 08-14-2025 05:59 AM Edited on 08-14-2025 06:00 AM
Not resolved, need support please
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.