FortiMail is a cloud service while FortiAnalyzer is deployed on-premises .
FortiMail need to send logs to FortiAnalyzer on-premises
You need to publish FAZ's port 514 UDP through a VIP, and add a firewall rule to allow syslog traffic from WAN to FAZ (with the VIP as destination) from FML IP only.
We are having 2 analyzers in 2 different subnet is this solution durable .
Do you have document for this solution
I don't have a specific document for this specific case (except the below one), but since there is no s2s VPN between the two equipment I don't know other solution for this case.
However I just noticed that FML supports OFTP (TCP 514).
https://docs.fortinet.com/document/fortimail/7.4.0/cookbook/811958
In that case you should use OFTP instead of Syslog, as OFTP is over TLS.
Your FAZ is behind some sort of Firewall anyways, so just allow one public IP to talk to FAZ over port 514 (udp/tcp depends on what you use).
You'll see an IP of your FCTEMS cloud instance once it starts to log
Thanks for your solution will apply this and update .
| User | Count |
|---|---|
| 2882 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.