Hi,
I have Fortigate 800C with Flow based Inspection and configured one arm sniffer on an interface and used 'config firewall sniffer' to enable ips sensor. And ips sensor used is default 'sniffer-profile' present on the Fortigate and selected to monitor and log.Below is config used for this. But, when i see on 'Log&Report', Sniffer Traffic is not displaying the packets received by this interface-port9.
set status enable
set logtraffic all
set non-ip enable
set interface "port9"
set ips-sensor-status enable
set ips-sensor "sniffer-profile"
Can anyone let me know is there any extra setting/config required for the IDS logging/reporting to work on Fortigate....?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.