Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
it8
New Contributor

Learning Report no data

I'm using a new FortiGate 80E, Firmware upgraded to v6.0.0 build0076 (GA).

 

Selected LEARN Action at the IPv4 Policy.

 

But The Learning Report no any data.

 

Can anyone help?

Thanks

 

 

1 REPLY 1
Nicholas_Doropoulos
Contributor

Hello, 

 

My first step would involve ensuring that traffic is indeed being matched by the policy that you have set to LEARN. The easiest way would be to right-click the policy and see the matching logs. It is possible for example that your traffic is being matched by another policy which would account for the fact that there is no data.

 

Once you've ensured that the traffic is being matched by the correct policy, you should ensure that logging is also enabled under Log Settings with the "All Sessions" option being enabled. 

 

If logging has been configured as well, generate enough traffic for the LEARN action to collect as much data as possible.

 

If it still doesn't work, then it's probably not supported by your specific model as per link below:

 

http://cookbook.fortinet.com/make-policy-learn-configuring-policies/

 

Focus on this particular section:

 

"Before getting into the details, it should be pointed out that because this feature requires a minimum level of logging capabilities, it is only available on FortiGates with hard drives that can be used for logging. Smaller models may not be able to use this feature. It some cases it is best to check in advance. An interesting example is the FortiGate 100 series. There is a small hard drive in the “100” units that deemed acceptable for logging in 5.2, but not in 5.4. If logging to the hard drive was enabled in 5.2 and then the unit was upgraded to  5.4, the Learning Report would be available. The challenge appears when you attempt to enable logging after the unit has been upgraded to 5.4. The option no longer exists, so even though you can enable a Learning Policy you would not be able to view the Learning Report. 

Recently, the hard drive issue in FortiGates became easier to address. In the more recent models, such as the “E” series, if the model number ends in a “0” it does not have an appropriate hard drive. If it ends in “1” it does. Therefore, a FortiGate 100E would not be useable for logging and therefore Learning Reports, but the FortiGate 101E would have a suitable hard drive and thus be fine for logging and the Learning Reports."

 

I hope the above helps.

NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3

NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors