Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Monitor attempted connections to VIP

I am relatively new to the Fortigate units and am trying to troubleshoot a connection problem to a virtual IP. I am trying to find out how to log all attempted connections so that I can see if the person having the problem is even making it to the address. I have a syslog server set up and it is I have the policy set to log and it is logging successful connections, but not attempted connections (for example if someone attempted to connect with a protocol not allowed by the policy). I have looked at the manuals and postings but haven' t seen how to do this. Sorry for such a basic question...
2 REPLIES 2
abelio
SuperUser
SuperUser

Hello and welcome, try using a new firewall policy with same src/dst but with ' deny' action and log it; obviously put this firewall policy at the end of your firewall policies list with similar src/dst. regards,

regards




/ Abel

regards / Abel
IPMAN
New Contributor

Abel' s suggestion works very well. You can also use the packet sniffer from the CLI to see realtime connection attempts. Something like: diagnose sniffer packet wan1 ' host xxx.xxx.xxx.xxx' where wan1 is your external port and xxx.xxx.xxx.xxx is your VIP
Dustin Niglio Payment Logistics Limited pcidss@paymentlogistics.com www.pcilogistics.com
Dustin Niglio Payment Logistics Limited pcidss@paymentlogistics.com www.pcilogistics.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors