Hi,
1. Using log aggregation authorization fails. On the manual page 171 (http://docs.fortinet.com/...inistration-Guide.pdf) . I can seet that manual says that we must configure password under FAZ server "config system aggregation-service" which is the same as on FAZ client. But there are no such commands available in the CLI. In the dashboard alert messages I can see alerts that log aggregation failed because of bad "auth method". How to enable password command? 2. I tried also with other option which is more granular - Fetcher management (page 173.). I have configured both sides with identical passwords and users, but when I press fetch now, other side does not receive request (also auth failed), and it can not be approved manually. I suppose that request could not be successful because log aggregation is not configured first of all.
Maybe some suggestions about the problem?
Regards,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
5.2 or 5.4 FAZ? 5.4 FAZ changed design and will use system settings admin user for client to authenticate (so no need to config password on server side but client side need to configure with correct server side admin user/pass)
Thanks
Simon
Got the same issue. Interested if there is a solution.
Hi, Mikael, is your issue also for 5.4 FAZ aggregate mode? is both client and server running on 5.4 and re-configured admin user/password on client?
Thanks
Simon
Hi Simon! Yeah, it is.
Running 2 VM:s that are using 5.4 software. One in Collector Mode and one is in Analyze mode.
I tried following a guide to the best of my abilities. But it was for 5.2 so some things have changed.
However, let me see if I can give you as much information as possible.
The FG that is acting as the device is only added in the Collector FAZ.
On the Collector I´ve setup a connection to the Analyzer under the Log Forwarding option under settings.
Using "Enable Log Aggregation" and a User and password is set.
Obviously I need to configure that on the Analyzer as well but the CLI command that did it for 5.2 doesn´t seem to be present in 5.4 How do I configure the Analyzer with the username and password?
How do I configure the Analyzer with the username and password?
-- on FAZ side, you need to configure the normal super_user profile admin user (same as the one you created for GUI/CLI login) and collector/client is to use this admin user for aggregate login in 5.4
Thanks
Simon
Hi LTC_FAZ,
For the #2 issue (Fetcher Management), it is independent
- you need setup a administrator (Standard or Super User) on FAZ Fetch server,
- then configure this user/pass on fetch client profile
Note: accessible devices will be limited in assigned ADOMs
Regards,
Shawn
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.