Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
llewesc1
New Contributor II

Trigger Event on the FortiGate from and Event Handler for FortiMail on the FortiAnalyzer

I currently have event triggers working on the FortiGate to ban IP's when the event handler on the FortiAnalyzer sees a matching event from the FortiGate. I also have an alert working within FortiAnalyzer for FortiMail when the event handler sees a matching event from the FortiMail.

 

I recall reading somewhere, when the FortiGate Event Handler is triggered, it only notifies the device from where it originated, which explains why I cannot get it to trigger on the FortiGate since it originated from FortiMail.

 

I'm trying to determine how I can ban an IP on the FortiGate from and event captured on the FortiMail using FortiAnalyzer. Is this possible? Has anyone done anything similar?

 

NOTE: In the images below, I have email alert configured instead ban IP for testing purposes.

 

Working Email Alert In FortiAnalyzer

Working Alert in FortiAnalyzerWorking Alert in FortiAnalyzer

 

FortiAnalyzer Event CountsFortiAnalyzer Event Counts

 

Not Working FortiGate Automation Stitch

Not Working FortiGate Automation StitchNot Working FortiGate Automation Stitch

 

FortiGate Event CountsFortiGate Event Counts

1 Solution
llewesc1
New Contributor II

Without making any changes to the automation stich, I was able to get this working by adding the FortiMail as a downstream device in the FortiGate Security Fabric.

SecurityFabric.png

 

View solution in original post

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello likewesc1,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
llewesc1
New Contributor II

Without making any changes to the automation stich, I was able to get this working by adding the FortiMail as a downstream device in the FortiGate Security Fabric.

SecurityFabric.png

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors