Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor

Log event when a WAN fails

Hello team,

 

We have 2 ISPs, connected to WAN1 and WAN2.

These WANs are in a SD-WAN with just the implicit rule, as "Spillover", with WAN1 as primary.

About 2 weeks ago, I took 2 of defaults "Performance SLAs", and added both WANs as participants:

These Performance SLAs, are: "Default_DNS" and "Default_Gmail"

Both performance SLA has:

Check interval: 1000 ms

Failures before inactive: 5

Restore link after: 10

 

IMHO, if WAN1 has a failure, after 5 seconds, everyone should use WAN2.  In this case, what event should be logged in the Fortigate?

How can I search for this?

 

I see events like the following, but no one tells me that a WAN was failing, 

* Member status changed. Member in sla.

* Number of pass member changed.

Also, all the events, are for "Default_DNS", no events for "Default_Gmail"

 

Thanks in advance.

Regards,

Damián

Damián Lozano
Damián Lozano
6 REPLIES 6
mpeddalla
Staff
Staff

Hello @damianhlozano  ,

 

Thank you for contacting the Fortinet Forum portal.

-In the event logs it shows only the switch of sla members and for additional logs, you can enable a few settings to verify, You can verify and monitor from sla packet loss on sd-wan GUI as in the below article to monitor the latency, jitter, and packet loss for each sd-wan member:

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/943037/monitoring-performanc...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-view-relevant-SD-WAN-logs-under-For...

 

Best regards,

Manasa.

 

If you feel the above steps helped resolve the issue, mark the reply as solved so that other customers can get it easily while searching for similar scenarios.

Manasa
AnthonyH
Staff
Staff

Hello damianhlozano,

 

Are you using SDWAN or Link-monitor to test for link failure? If it is SDWAN I believe there is a event log called,  "SDWAN SLA status warning". You can create an automation stitch based on this event log trigger to send you an email.

Technical Support Engineer,
Anthony.
damianhlozano

Hello Anthony!

This is SDWAN.

There is no event log called "SDWAN SLA status warning"

When creating a stitch, appear the following:

* SDWAN SLA information

* SDWAN SLA information warning

* SDWAN SLA notification

Damián Lozano
Damián Lozano
vbandha
Staff
Staff

Hello @damianhlozano 

 

The logs you mentioned would be the ones you check:

* Member status changed. Member in sla.

* Number of pass member changed.

 

You will see Member in SLA and Member out of SLA when their status changes.

 

It will show you based on member ID and you can check which WAN has the mentioned member ID:

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/942095/sd-wan-members-and-zo...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-log-for-SLA-in-SD-WAN/ta-p/2...

 

Regards,

Varun

damianhlozano
Contributor

Hello everyone!!

 

Thank you for your answers!!!

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-log-for-SLA-in-SD-WAN/ta-p/2...

Here, he said: 

set sla-fail-log-period <x>

set sla-pass-log-period <y> 

FortiGate will keep the logs for 10 minutes. For longer retention, we should have an external storage like FortiAnalyzer.

Related to this, I have 2 more questions:

* For example, If I configure "set sla-fail-log-period 30", this means that if WAN1 is failing, while the status does not change, a log should be record, each 30 seconds, right?

* Is there a way to keep more than 10 minutes without FortiAnalyzer?

 

Thanks.

Regards,

Damián

Damián Lozano
Damián Lozano
parthpatel

Hello @damianhlozano,

* For example, If I configure "set sla-fail-log-period 30", this means that if WAN1 is failing, while the status does not change, a log should be record, each 30 seconds, right?
That's correct 

* Is there a way to keep more than 10 minutes without FortiAnalyzer?
Without external logging logs will be retained on memory/disk and will rollover based on the space available

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors