Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kelv1n
New Contributor

Get firewall to use a VPN / Specific interface for sending logs?

Hi Guys

 

I've got a curious issue, I'm trying to send logs from our Fortigate to our FortiAnalyzer through a VPN. The VPN is connected to the same Firewall which should be sending the logs. 

 

The problem is the requests keep timing out, and checking the local traffic logs (see attached screenshot), it looks like the Firewall is using our WAN (as source IP is our public IP) but the Src interface is "known-0". But I need the Firewall to use the LAN interface -> OFFICE-VPN.

 

I'm not sure if its relevant, the VPN is working fine (Its a Fortigate 200D at each end, configured using the built in wizard), I can ping devices on each side - but if I use the Firewall CLI, I can't ping devices. So it looks like and interface routing issue.

 

Is there anyway of forcing a specific interface? or any suggestions to get round this.

 

Many Thank

6 REPLIES 6
kelv1n
New Contributor

For anybody who may suffer from a similar issue - Basically when configuring a FAZ or FMG you need to do it via the CLI, there is a source-ip setting which you set to the same address as the interface you want to send from. This then ensures the traffic is routed correctly.

 

It appears to work at least.. Fortigates are frustrating!

Chura
New Contributor

Pretty much every service (syslog/monitor/tacacs/radius etc) will have the option to choose source-ip from CLI.

The gui is there to fit basic day to day needs. I find it right that advanced things are CLI (Job security hmmm hmm).

 

On thing I hate that I can't modify its source-ip is the SSLVPN Web application source IP (when you add VPN to the party)

//Chura CCIE, NSE7, CCSE+

//Chura CCIE, NSE7, CCSE+
kelv1n
New Contributor

Thanks Chura, thats good to know for future reference.

 

I've just swapped us from Palo Alto where 95% of functionality is available in the UI, so still finding my way around (hence the frustrations). Out of interest I've noticed Fortinet do make substantial UI changes (removing, changing layout, moving to CLI etc). Does this not drive you guys nuts?

 

I don't mind the CLI, its probably the simplest and most logical I've worked with for a while.

soonguan

 

 

billflu
New Contributor

Here is the command I had to use in FortiOS 5.2

 

config log fortianalyzer setting

set source-ip x.x.x.x

FB
New Contributor

it really helped me!

i was facing the same problem because we´re changing from MPLS to a VPN connection, so, we need to configure faz to use the VPN insted local LAN1 port, b ut even routes being properly configured, no connection.

 

Ping was working only with source-ip option, but thre is no similar for tarceroute, then, the idea, maybe the FAZ has the same problem as some 60c models where the source is weirdly automagically configured as an interface you don´t want to use...

 

---

---
Labels
Top Kudoed Authors