Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DaleH
New Contributor

How to change logged IP address

Hi, We have a Fortigate 100D and I have an issue with how the logging of traffic is stored in the Traffic log. I' m trying to check what external connections have been made to our mail server in the traffic log report. When I check the report and filter by the destination IP address using our mail server internal IP address, I only see the blocked connections (which are all valid). If I filter the traffic log by destination IP address using our external IP address, I can then see all the successful connections to our mail server, plus all the other successful inbound connections. So, is it possible to make successful inbound connections store the interal IP address for the connection like it does for blocked connections? It would make life so much easier checking the logs by only having to look in one place and getting all the data without having to apply further filters. Regards, Dale.
2 REPLIES 2
ShrewLWD
Contributor

Hi Dale, For the rule that allows the inbound traffic, do you have (4.3) Log Allowed Traffic / (5.0) Log All Sessions, enabled? It is going to add a lot more data to your logging though.
DaleH
New Contributor

Yes, we do. And I think that is maybe the source to why there are differences in the logging. * The items logged with the internal destination IP address are logged by a block policy. * The items logged with our external IP address are logged by our allow policy. Bit of a quirk, but that is all I can see different.
Labels
Top Kudoed Authors