Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sasa_g
New Contributor

Short review of 5.0.1 and 5.0.2

I have been using FortiAnalyzer for long time now on different versions of firmware. And curently it is collecting logs from more than 70 Fortigate devices. I don' t understand point of new versions of FortiAnalyzer. First of all it is exactlly the same as FortiManager without Device and Policy management. So question is why would I even consider investing in FortiAnalyzer when everything works on FortiManager. Even in address bar links are ' https://XXX.XXX.XXX.XXX/fortimanager.htm?action=login' Secondly features like sending email when defined filter has a match in some device log are omitted. It is the key feature of log management!!! To be alerted when some for example IPsec tunnel goes down. I know that it can be done on device but first it isn' t even remotely granular like on FortiAnalyzer 4.3, and second where is centralized management in that!? All in all this is big step back, as some critical features were removed and all that is left is part of FortiManager (which I also have). Only good thing is that for two days of production work I didn' t noticed any serrious bugs. (There are lot of minor issues but they can be ignored) It seams like Fortinet is going to put End of Life on FortiAnalyzer series of products because for customers, there isn' t any reason to invest in FortiAnalyzer if You have or had invested in FortiManager, and if You don' t need FortiManager than probably FortiCloud is good enough. For my company FortiCloud is not an option due to regulations and laws.
3 REPLIES 3
emorillo
New Contributor

We don' t need FortiManager because we only have a few fortigates, but we need reports for our customers and we depend heavily on FortiAnalyzers to produce the reports. We cannot use Forticloud due to the nature of our customers, rules and regulations. So I think each company has different needs and the FortiAnalyzer is here to stay. FG300 HA FG300 HA FG200 HA FG620 HA FG620 Standalone. FAZ100C FAZ1000C FAZ1000C
RH2
New Contributor II

Yeah, it would have been nice to know that the manager was getting the analyzer features before we upgraded both! Of course we went with a virtual manager and so far 5.0.2 is unusable, had to downgrade to 5.01. And they really need to provide some useful report templates, for some reason they think the only thing we care about is the top whatever!
billp
Contributor

Make your voice known with your sales rep if you don' t like the reports. Until recently, it hasn' t been clear to upper management that better reporting could drive sales. Here' s what I learned from a FTNT engineer: FAZ and Fortimanager will likely merge into a single platform. For those that only need FAZ functions, the FortiManager bits would be disabled. 5.0.3 should be the first deployable version of the new FAZ. Expect something in May/June. It should be a major update. They acknowledge that a single per-user forensic " pink slip" report is missing from the product. They are working on it as well as including more useful reports instead of things like " top x Youtube requests" .

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors