Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cerede2000
New Contributor

VPN SSL log

Hi everybody,

 

I have issue with VPN SSL logs.

VPN logs are empty :(

 

I have check settings in Log&Report > Log Config > Log Settings checkbox VPN activity event are check and Event Logging, Enable All are checked too.

 

Why connections are not write in log ?

 

FortiGate 60C in 5.2.3

 

Thanks :)

9 REPLIES 9
emnoc
Esteemed Contributor III

What do you have enable in config log global setting for gui logs locations

 

e.g

config log setting

 

  set gui-location "memory|fortiguard"

 

end

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
cerede2000

Only memory is configured and don't have fortiguard

emnoc
Esteemed Contributor III

So do you have a tunnel-client enabled and authenticated?

( check in the vpn ssl monitor )

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
cerede2000

Yes and when users is connected I see live connection in SSL VPN monitor.

 

But I want connection history :)

techevo

Hi, I have the same issue with a cluster of 310B under 5.2.5 ( was the same on 5.2.4 ).  There is no hdd on the 310B so it only log to memory.  I looked at my 60D that log to memory and to forticloud and this one shows SSLVPN logs.  So I tested removing forticloud and sure enough it no longer log SSLVPN connection in logs.  My 100D cluster log to disk and the SSLVPN logs are there. I guess for device that log only to memory we are out of luck.  I did not find anything under CLI that would enable vpn under memory logs.  Unfortunatelly there is too much traffic on my 310B cluster to do anything interesting with forticloud as after 20 minutes I bust my free space for the day.  I might try removing logging from most items and see if I can make it last the day ( if I ever have time to play with that ! )

awasfi_FTNT
Staff
Staff

Try the following:

 

config system settings

set [size="2"][size="2"][size="2"]vpn-stats-log [/size][/size][/size]{ipsec | l2tp | pptp | ssl}

end

 

You can add multiple

AWASFI
cerede2000

No changes :(

Add also set vpn-stats-period 300

 

But no logs :(

awasfi_FTNT

Do you see other logs (traffic logs, security logs,..etc)?

 

Note: logging to memory is limited and old logs will be replaced very soon as logs will fill up the memory quickly, it's not like disk logging.

 

I recommend to upload logs to FortiCloud and check again. If still an issue may be upgrade to v5.2.5 will fix the issue or you will need to contact support to investigate.

 

Regards,

AWASFI
cerede2000

Yes, Traffic log, system log is ok.

 

I'vs create FortiCloud Account now, I initiate VPN SSL connection but it's not appear :(

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors