Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

What is the difference between logging UTM sessions and all sessions in the FW?

What happens if it is a "normal" firewall rule without any filtering applied?

1 Solution
adimailig
Staff
Staff

Hi,

When "Log Allowed Traffic" in firewall policy is set to "Security Events" it will only log Security (UTM) events (e.g. AV, IPS, firewall web filter), providing you have applied one of them to a firewall (rule) policy.
'Log all sessions' will include traffic log include both match and non-match UTM profile defined.

Reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-Security-Events-and-All...

If there is no Security Profile enable on firewall policy and "Log Allowed Traffic" is set to "Security Events", then there will be no log generated by firewall policy.

Best Regards,

Arnold Dimailig
TAC Engineer

View solution in original post

1 REPLY 1
adimailig
Staff
Staff

Hi,

When "Log Allowed Traffic" in firewall policy is set to "Security Events" it will only log Security (UTM) events (e.g. AV, IPS, firewall web filter), providing you have applied one of them to a firewall (rule) policy.
'Log all sessions' will include traffic log include both match and non-match UTM profile defined.

Reference : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-Security-Events-and-All...

If there is no Security Profile enable on firewall policy and "Log Allowed Traffic" is set to "Security Events", then there will be no log generated by firewall policy.

Best Regards,

Arnold Dimailig
TAC Engineer
Labels
Top Kudoed Authors