Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
harald21
Contributor

Logging at " implicit deny" policy

Hello, I' m using a Fortigate 310B-Cluster (FOS 4.0.4) together with a FortiAnalyzer FA-100C (FOS 4.2.2). At the FAZ I can see that the traffic log is flooded by deny events with a policyid=0. As this is the " implicit deny" policy, how can I change that this thaffic is no longer logged? Sincerely Harald
7 REPLIES 7
willem
New Contributor

Just edit this policy and uncheck the logging-box. But by default it is unchecked, so you must have checked it once?
Willem __________________________________ FCNSP (Fortinet Certified Network Security Professional)
Willem __________________________________ FCNSP (Fortinet Certified Network Security Professional)
harald21

Hello willem, " uncheking" the logging box is not an option as in FOS 4.0.4 this policy is not visible! Because this policy is not vissible, I never checked this box! In FOS 4.0 MR2 the policy is vissible, but at the moment a firmware upgrade is not possible. Sincerely Harald
ede_pfau
SuperUser
SuperUser

 conf sys global
    set loglocaldeny disable
 end
 
valid for all FortiOS versions.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
harald21

Hello, thanks for the hint. Unfortunately this is already set at my Fortigate. According to the documentation this setting enables/disables logging of connection attempts to the local fortigate unit. In my case denied connections attempts to remote IP' s are logged. Sincerely Harald
red_adair
New Contributor III

i believe this is: config log {fortianalyzer | memory | syslog} filter set other dis end -R.
ede_pfau
SuperUser
SuperUser

super, nearly:
 config log memory filter 
    set violation disable 
 end
 
thanks red.adair for the right hint!
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
harald21

Hello, thanks for the hints, I have set config log fortianalyzer filter set violation disable end Unfortunately, this does not work. I will open a support ticket on this! Sincerely Harald
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors