Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CCIEKW-HOTMAIL
New Contributor II

FortiMail is a cloud service while FortiAnalyzer is deployed on-premises

FortiMail is a cloud service while FortiAnalyzer is deployed on-premises .

FortiMail need to send logs to FortiAnalyzer on-premises

5 REPLIES 5
AEK
SuperUser
SuperUser

You need to publish FAZ's port 514 UDP through a VIP, and add a firewall rule to allow syslog traffic from WAN to FAZ (with the VIP as destination) from FML IP only.

AEK
AEK
CCIEKW-HOTMAIL
New Contributor II

We are having 2 analyzers in 2 different subnet is this solution durable .

Do you have document for this solution

AEK

I don't have a specific document for this specific case (except the below one), but since there is no s2s VPN between the two equipment I don't know other solution for this case.

However I just noticed that FML supports OFTP (TCP 514).

https://docs.fortinet.com/document/fortimail/7.4.0/cookbook/811958

In that case you should use OFTP instead of Syslog, as OFTP is over TLS.

AEK
AEK
igranrene
New Contributor

Your FAZ is behind some sort of Firewall anyways, so just allow one public IP to talk to FAZ over port 514 (udp/tcp depends on what you use).
You'll see an IP of your FCTEMS cloud instance once it starts to log

https://xender.vip/
CCIEKW-HOTMAIL
New Contributor II

Thanks for your solution will apply this and update .

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors