Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Remko_Oude_Elferink
New Contributor

Log stopped after 10 seconds

We have 2 Fortigate 400a in a cluster. Since 3 weeks we do not get any logs in our FG Analyzer. If i reboot 1 FW device in the cluster we get about 10 seconds of logging then it shuts down again.. I have checked/compared all settings with another FW Cluster in our network who is succesfull in reporting to the same Analyzer. What could be the problem? Firmware version is: Fortigate-400A 3.00-b0744(MR7 Patch 6) FortiOS 3.000 (Expires 2010-10-18)
4 REPLIES 4
abelio
SuperUser
SuperUser

Hi and welcome,
What could be the problem?
to begin to catch one, try with built in sniffer using CLI commands like: diagnose sniffer packet any " port 514" diagnose sniffer packet any " host <your_FAZ_IP> and port 514" etc regards,

regards




/ Abel

regards / Abel
Remko_Oude_Elferink
New Contributor

diagnose sniffer packet any " port 514" I get a lot of information. diagnose sniffer packet any " host <your_FAZ_IP> and port 514" I get a lot of information. seems to work ok.. but the information does not show up in the analyzer..
abelio

ja visst... but in that ´lot of information' , can you see any ' rst' ? I mean, if you' re seeing ' syn' and ' ack' between your box and your analyzer, there' s good traffic. Did you repeat the sniffer command on the analyzer side? Same thing? Is the device already registered in your analyzer with appropiate values, disk size allocated, device permission for send logs?

regards




/ Abel

regards / Abel
Remko_Oude_Elferink
New Contributor

It works again.. I have updated the firmware on the FW from MR7 Patch 6 to Patch 9 and the analyzer is showing the logs again..
Labels
Top Kudoed Authors