Hi guys, we have a problem with sending logs from FGT60E (5.4.4) to FAZ200D (5.4.3) Once in a while (about once a week), FortiGate stops send logs to the FAZ. In Device Manager I see the red status instead of green. If I restart the FAZ, the problem persists. Reboot FGT will help. The FGT-> FAZ connection test passes OK. We have 8 units connected to the FAZ and only this one does.
Some idea or diag cmd?
config log fortianalyzer setting
set status enable
set ips-archive enable
set server "xx.xxx.xxx.xxx"
set enc-algorithm default
set conn-timeout 10
set monitor-keepalive-period 5
set monitor-failure-retry-period 5
set source-ip ''
set upload-option realtime
set reliable enable
end
Thanks. Jirka
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi you can try to disable encyption, same case and it's working fine now.
Don't forget to set source IP if your FGT is on remote site (VPN)
config log fortianalyzer setting set enc-algorithm disable
set source-ip LAN-IP
end
2 FGT 100D + FTK200
3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Hi Baptiste,
Unfortunately, I tried it all without success. FGT is not on the remote side so I set scr-add as a WAN address and disable encryption. I rebooted and it worked for 5 days. Today again the same mistake...
Is there any way to diagnose what's wrong?
Thanks
Jirka
Yes disable ENC it's not supported going forward ( FAZ 5.4.2+ ) . Also running diag sniffer packet any "host <insert address of FAZ>" and see what's happening will give you an ideal.
Just generate a traffic event/system event and monitor for traffic to FAZ device or use the "diag log test " and watch for a log event.
You can run "diag debug application miglogd -1" and look for the faz message also an alternative
http://socpuppet.blogspot...cloud-issues-52ga.html
PCNSE
NSE
StrongSwan
ok, in the Release Notes for FortiOS 5.4.5 is: BUG ID: 421062 FortiGate 60E stopped sending logs to FortiAnalyzer when reliable enabled.
Now I've updated FGT60E to FortiOS 5.4.5, so let's see..
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.