Hi,
I have a FortiGate 3040B (v5.2) connected via an IPsec VPN tunnel to a FortiGate 60D (v5.4) installed on a remote site.
On the FortiGate 3040B, in the "Traffic log" -> "Forword Traffic", I don't have any log about DNS. If I put the IP address of the DHCP and DNS server in the Source IP and the IP address of a PC behind the Fortigate 60D in the Destination address, I look only DHCP packets.
Someone could explain me why ?
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
do you mean no dns related traffic log if put filter on source ip address using both dhcp and dns servers ip?
did you filter on GUI or cli?
Yes, the DHCP and DNS services are on the same server, so the same IP.
On the FortiGate 3040B I can see DHCP packets in both directions, but DNS packets only in ingress.
I filter in GUI and I have the same results with a syslog server
Thank you
Are you only logging UTM events on your policies or are you logging all sessions?
Mike Pruett
I Mike,
all sessions
Are you able to see the traffic (DNS etc) if you do a packet debug? (diag deb flows and traces)
Mike Pruett
I Mike,
yes, with the command diagnose sniffer packet I see DNS traffic.
So, you think it is a GUI problem ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.