Hi all! How to extend VPN connection events via Forticlient, I need to add the hostname field to the logs.
Hi CVE
Do you mean you want to see client hostname on the FortiGate logs?
Hello AEK! Yes sir, right, i wanna to see client hostname in FortiGate logs. because I need client hostnames to correlate with other logs in SIEM system.
Hi CVE
FGT can get the hostname by reverse DNS lookup for the IP address.
When a client is on-fabric usually the hostname/IP record is updated on the DNS server, I think is it done via LDAP's DHCP server.
But with VPN by default the IP address is provided by FGT, not AD's DHCP server. So for VPN you need something to update the related DNS record on your (corporate) DNS server from which your FGT is resolving the addresses, or simply use LDAP's DHCP to provide your client host with the dynamic IP.
I hope I'm not wrong but it should be something like that. I think you should dig on this side.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
764 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.