Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sambhu
New Contributor III

FAZ for the SDWAN -IPSec down monitor

Hi,

 

 I’m trying to use FortiAnalyzer (FAZ) to monitor IPsec tunnel down events in a large-scale SD-WAN.

Event Handlers are in place and SMTP email alerts are configured, but I’m seeing:

  1. IPsec down events don’t always generate alerts.

  2. FAZ is at HQ. When the branch-to-HQ IPsec tunnel drops, FAZ doesn’t trigger the down alert. I usually get a “down + up” alert only after the tunnel comes back up, which isn’t useful.

If this isn’t a valid use case for FAZ, what’s the recommended way to achieve timely alerts? Can FAZ generate a “device disconnected” or “device down” event when a FortiGate loses connectivity to FAZ? That would be more meaningful once the tunnels drop.

1 Solution
PhiPhan
New Contributor II

You need to check the log of FAZ and create a event from it, not the log from ADOM.

View solution in original post

10 REPLIES 10
Sambhu
New Contributor III

Not resolved, need support please

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors