On location A I have a FG61E (v5.4.8) paired with a FortiAP 221C and a FortiAP 21D (both with the v5.4,build0371) and I'm seeing in the "Wifi Events" the message on the title being logged at a crazy rate (dozens of times per minute). The setting "Enable Rogue AP Detection" is disabled. Details of this event as an example:
General Date 04/04/2018 Time 12:42:30 Virtual Domain root Log Description Wireless station presence detection (...) Action Action sta-presence-detected Security Level Event Physical AP FAP21D... (...) Message Station presence detected, MAC (...)
Of all the Fortigates + FortiAPs that I have on the field, I'm a seeing this event being logged for the first time. On location B I have another 61E paired with a FortiAP 320C (same 5.4 builds as in location A) with virtually the same settings regarding WIDS, AP Profiles and Logging (with "Wifi Events" checked), but on location B there are no Logs whatsoever regarding "Wireless station presence detection". Both locations are in the city dense areas with many foreign AP around.
It is not a problem per se, but it it unnecessary, a waste of CPU resources and disk space for (useful) logging, and therefore I would like to somehow disable the recording of this event. Has anyone ever faced the same issue?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
After having many thousands of log pages filled in the last few days (screenshot attached), I figured out that having either "Frequency Handoff" or "AP Handoff" activated triggers the constant logging of this event (sta-presence-detected), so for now they remain turned off (although AP Handoff is desired on this deployment).
Like previously mentioned, I have the same kind of setup on other sites (eg. 100D + 320B + 221C [latest v5.2] or 61E + 320C [latest v5.4]) with both "Frequency Handoff" and "AP Handoff" activated on all AP profiles, and this event flood is nowhere to be found.
I'm still searching around in KBs and Handbooks for possible hints about this, but so far without luck (I'll open a support ticket if get nowhere).
Same problem here. Please let us know your findings after working with Fortinet tech support.
We have same events logged.....thousands of pages.
FGT 140D latest 5.4 release
Update: this issued went away when we upgraded our 61E units from 5.6.13 to 6.0.12
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.