Hi all,
I have a Fortimanager managed set of Fortigates.
For reasons unknown I don't see any logs of those successfully logging into the SSL VPN.
I've searched high and low but can't find anything in Fortimanager to deploy to change this behaviour?
Any pointers most appreciated!
Cheers
Jon
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hey Jon,
first thing to check would be if FortiGate even generates the logs; if you have FortiGates without disk, then they probably don't log this by default.
You can see a FortiGate's logging settings in FortiManager > Device Manager section; you might need to enable additional visibility under the Tools menu, though.
If you still can't find anything on logging (this may depend on firmware version of the Manager), then enable CLI options in the Tools > Visibility menu, and then navigate to 'log' on the tree under CLI to find the CLI equivalent of logging settings.
Check the following:
'config log memory setting' -> is this enabled?
'config log memory filter' -> is this 'severity' set to warning? If yes, change this to information so FortiGate logs all logs
-> please do note that this will have an impact on FortiGate memory usage
'config log eventfilter' -> is 'vpn' set to enabled?
Cheers,
Debbie
Hi Debbie,
We're using FAZ so those logs should have gone through to there?
It's just an easy thing, I thought, just to record who logs in successfully lol!
Cheers
Jon
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.