I am trying to figure out where device info comes from on Forward Traffic logs on Fortigate devices. The source will show an ip address and the device will have a different ip address. This causes some confusion when trying to investigate log data. Thanks in advance.
hi,
if im not mistaken, it comes from Device Detection, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-Device-Detection-to-allow-FortiOS-t...
can you share an example of a log where the log shows an ip and in fact has another ?
Is the device behind another router/firewall?
In the forward log the "source" column will show a user icon with a name and an ip address. In the device column it has a windows logo with a different IP.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.