- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Increasing Log Visibility for IPSEC VPN Issues on VDOM in Fortigate 7.4.4
Hello,
I am a user of Fortigate 7.4.4. I have an architecture based on a root VDOM, where my WAN connections arrive, and then interconnection links with my child VDOMs (as shown in this diagram visible in the Fortigate documentation).
My infrastructure is shared with a client. My client wants to set up an IPSEC VPN on their VDOM but is encountering problems and needs logs.
The logs are not very verbose, and there are even no logs in the FortiGate GUI for their VDOM. I have to use the CLI (still within their VDOM) to provide them with traces. What can I do to give my client more visibility?
Thank you for your help.
Solved! Go to Solution.
- Labels:
-
FortiAnalyzer
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @5q46n2te8jPWJY,
By design, the VPN event logs provide a generic overview/error messages of issues concerning the VPN but ultimately you will require CLI debugs to obtain more detailed information when investigating.
Best Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @5q46n2te8jPWJY ,
Your client could use the debug commands from CLI to troubleshoot, they are more useful than simple logs:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-IPsec-Site-to-Site-T...
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955
Best regards,
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I already read that. But my client don't want to use CLI and want to use GUI logs. Is there a way he can use ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @5q46n2te8jPWJY,
By design, the VPN event logs provide a generic overview/error messages of issues concerning the VPN but ultimately you will require CLI debugs to obtain more detailed information when investigating.
Best Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @5q46n2te8jPWJY ,
As previously suggested the CLI provides you much more useful outputs for troubleshooting. If your customer wants to use only GUI logs, they will be very limited in troubleshooting, majority of the debug outputs are available only from CLI.
Best regards,
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @5q46n2te8jPWJY ,
Kindly refer below KB where it might be thing that you are looking for.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-stop-sending-logs-to-FortiAnalyzer-...
