Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fionaC
New Contributor II

Syslog over TLS with local CA - has anyone gotten this to work?

Hi All,

I have a syslog server and I would like to sent the logs w/TLS.

My syslog server has a certicate assigned to it from my local cert authority which is a Windows CA

I uploaded my cert authority cert to the Fortigate but still does not work.

THas anyone gotten TLS syslog to work when the CA is a local Windows CA that shows under remote certificates?

1 Solution
jiahoong112
Staff
Staff

Kindly refer to this document as it may be helpful for syslog over tls: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Send-Syslog-over-TLS-to-a-rsyslog-server/t... 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**

View solution in original post

4 REPLIES 4
AEK
SuperUser
SuperUser

Hello

I didn't do that before, but here FortiGate is a syslog client, so as per my understanding if you added your CA certificate to your FortiGate then it will trust the syslog server's certificate, and you don't need to specify a special SSL client certificate on your FGT unless your syslog server requires it, because usually servers don't require a trusted client certificate, but clients do require a trusted server certificate.

The below may also help:

  • Check "config log syslogd setting" is all parameters are correct and compatible with your syslog server  (port number, SSL version, log format ...)
  • Check syskog server logs (usually /var/log/syslog on Linux), it may indicate why logs are not accepted from client
  • Try sniff traffic from server side to see if any traffic is received from FGT on the right port
  • Check if your syslog server checks client certificate. In case it does then you need to use a valid client certificate on FGT, otherwise you still can disable client certificate check on server side
AEK
AEK
jiahoong112
Staff
Staff

Kindly refer to this document as it may be helpful for syslog over tls: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Send-Syslog-over-TLS-to-a-rsyslog-server/t... 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
fionaC
New Contributor II

I got the certificate to work...still cannot get the logs to work. That is a different issue. 

rosatechnocrat
Contributor II

@fionaC : Please visit below link to set the certificate and send logs in TLS encrytped. 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-send-encrypted-logs-to-Syslog-serve...

Rosa Technocrat -- Also on YouTube---Please do Subscribe
Rosa Technocrat -- Also on YouTube---Please do Subscribe
Labels
Top Kudoed Authors