Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
neonbit
Valued Contributor

Possible to enable extended-utm-log for application control?

Hi all, Do you know if there' s a way to enable the extended-utm-log functionality on the FortiManager for the application control on 5.0.6? The application control profiles don' t have the advanced settings (like the antivirus profile) where it lets you enable the field. If I change it manually via the CLI on the FortiGate the changes will be reverted the next time I push the policy from the FortiManager. The only way I can see is if I import the policy from the firewall, but this will also import the interfaces again (and try to remap them to zones), so I' m thinking there' s got to be an easier way.
3 REPLIES 3
neonbit
Valued Contributor

Fortinet TAC have confirmed that this feature will be available in the next release (5.0.7). The extended-utm will be enabled for the rest of the security profiles.
AndreaSoliva
Contributor III

Hi I' m not same opinion as metnioned here in this notes. If you use FortiOS 5.0.6 the log to be enable is: # config application list # edit [Name des Profile] # set extended-utm-log [enable | disable] # set log [enable | disable] # set other-application-log [enable | disable] # set unknown-application-log [enable | disable] # end All this logs to be enabled and more see following article: https://forum.fortinet.com/FindPost/106588 I enabled all these logs meaning full logging and can see on FAZ/FMG all this logs. From this point of view is already today possible. Why the TAC says only with 5.0.7 I do not really know. hope this helps have fun Andrea

Sean_Toomey_FTNT

If you don' t see this option in FMGR GUI, it is always possible to use a CLI script to accomplish this. What you do is ensure Scripting is enabled under System -> Admin -> Admin Settings. Go to Device tab and create a new CLI Script under the Script section. Use the same CLI commands you would use as if you were typing them into a FortiGate. config application list edit <MyAppProfileName> set extended-utm-log enable end Override the target on the script and choose the option for Policy Package/ADOM/DB Run the script against the policy package or ADOM required. This will then change the profile accordingly on the FMGR database and push out next time you push policy. Hope this helps!
-- Sean Toomey, CISSP FCNSP Consulting Security Engineer (CSE) FORTINET— High Performance Network Security
Labels
Top Kudoed Authors