Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Globally disable traffic log for specific service

Hello

We want to globally disable traffic log for specific service (e.g. DNS), not at policy level.

Anyone nows if we can do that on FortiGate?

AEK
AEK
1 REPLY 1
pminarik
Staff
Staff

"Log-level" (no / utm-only / always) of traffic sessions is an attribute of firewall policies, it cannot be configured anywhere else. If you require to not log specific traffic, you will need to create specific policies for it with logging expicitly disabled.

 

The only exception to this would be when using Security Fabric, which mandates enabled traffic logging in all policies.

[ corrections always welcome ]
Labels
Top Kudoed Authors