Hello,
I recently setup an explicit proxy to allow us to view traffic to an internal site. I want to see who is using the site, and how often, but I can't seem to find the information in my logs. So, here's my setup, and hopefully someone can help shed some light on this for me :D
Fortigate 300C - FortiOS 5.2.3
Policy & Objects -> Explicit Proxy -> Logging options -ON Log allowed Traffic (All Sessions) - Policy is enabled
I have the AD SSO plugin
Log Traffic is being forwarded to a FortiAnalyzer-200D - 5.2.1
So first, what traffic type am I looking for? Should this be webfilter data, or traffic data?
Will it retain the user names from AD?
Is this even the right way to do this? I know I can see the traffic now with webfilter data if it's from a vpn'd users(not proxied), but internal users, when not using the proxy, wouldn't show up as the traffic didn't go through the fortigate unit.
Any help would be greatly appreciated!
Thanks.
Ed
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.