Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dominikw
New Contributor II

Why you should NOT use 5.x OS

Hi ! I just upgrade device (FG60B to FG60D) and I wanted to use new FortiOS (5.0.5). I usually avoid fresh firmware (x.0.0, x.0.1, x.0.2) Before that I always used 4.x (usually 4.3 last MR) on my customers devices and everything was OK. In 5.0.5 I can' t find some things (GUI), some seems to have problems (GUI). 1. I can' t find " log & archive statistics" widget 2. In firewall policy I cannot create IPsec policy (in GUI, in CLI I could do it) 3. Log events are not working (always empty). 4. In event logs pane - section AV, WebFilter, AntiSPAM, IPS are gone ??!!! 5. In Security profiles I can edit only default profiles (but I can see and select more in FW policy rules). What the f**k happened to Fortinet ??? That is not 5.0.0 or 5.0.1 or even 5.0.2 ! That is not beta program !!! Many useful things seems to be gone. Are they going to lose their customers and partners ?

Dominik Weglarz, IT System Engineer

Dominik Weglarz, IT System Engineer
16 REPLIES 16
dominikw
New Contributor II

If anyone find futures that Fortinet removed (especially from GUI) please let us know.

Dominik Weglarz, IT System Engineer

Dominik Weglarz, IT System Engineer
TMX1
New Contributor

Dominikw: I was told by their tech support that the Log and Archive Statistics has been removed. I was also told if i wanted to get that widget back, I would have to make a " New Features Request" . They are complete monkeys in my opinion and I know plenty other Fortigate users which are really pissed off with the lack of quality control. They keep changing stuff and breaking other things repeatedly. Getting sick and tired of this myself.
emnoc
Esteemed Contributor III

For all the negatives on 5.0.5 you have a few positives. But I will try to address some of the issues that you posted 1. I can' t find " log & archive statistics" widget The gui has gotten clutter over time and that widget has been removed. Fortinet is pushing you to forticloud for logging statistics. It’s off appliance and actually better. Get use to it, they are not going to go back and clutter the GUI dashboard 2. In firewall policy I cannot create IPsec policy (in GUI, in CLI I could do it) Policy-based vpns are long gone imho, & as the best common practices for vpns 3. Log events are not working (always empty). I don’t seem to have that problem. How are you configuring the log setting? Did you format the log disk ? Also you have to enable the status enable i.e config log memory setting set status enable end And the same applies for disk logging. 4. In event logs pane - section AV, WebFilter, AntiSPAM, IPS are gone ??!!! See the above. Fortinet is pushing us to start using forticloud logging. But these features are still available. . In Security profiles I can edit only default profiles (but I can see and select more in FW policy rules). Do you have an example on what your talking about?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Jordan_Thompson_FTNT

Hi Dominik, See below for answers to some of your questions.
1. I can' t find " log & archive statistics" widget
This feature has been removed from 5.0.
2. In firewall policy I cannot create IPsec policy (in GUI, in CLI I could do it)
Policy-based IPsec is disabled by default. The preferred method is interface-based IPsec. If you would like to use policy-based, you can enable it under " System -> Config -> Features" on the GUI. There is a " Policy-based IPsec VPN" option.
4. In event logs pane - section AV, WebFilter, AntiSPAM, IPS are gone ??!!!
Are you referring to the " Security Log" section? The individual security feature logs are disabled by default as the same information is available in the traffic log. If you' d like to restore those sections, you can enable " extended-utm-log" in the CLI for the relevant security profiles. The log menus will show up after logs are available. Please also confirm that the correct log device is selected under " Log & Report -> Log Config -> Log Settings" for " Display Logs From" .
5. In Security profiles I can edit only default profiles (but I can see and select more in FW policy rules).
Similar to policy-based VPNs, editing multiple security profiles is disabled by default on desktop platforms. To enable it, visit " System -> Config -> Features" and enable " Multiple Security Profiles" .
simonorch
Contributor

If you' re not getting any logging even if configured then try formating the log disk.

NSE8
Fortinet Expert partner - Norway

NSE8Fortinet Expert partner - Norway
dominikw
New Contributor II

Thank you all guys ! @TMTX1 - I wanted to give A - my wrong click ;) @emnoc - config log memory ... - you were right - now I can see it (in GUI it was memory checked but not worked before CLI change) The same story with disk. @jthompson - " System -> Config -> Features" on the GUI. There is a " Policy-based IPsec VPN" option and I can see IPsec in policy ! Similar " Multiple Security Profiles" @simonorch - it wan no need - emnoc & jhtompson suggestion was good. I start feeling like I' m in home ... I think that model 60D has some issues. I don' t have " Security Log" sectiona at all (I can see it in FWF60C) There is also no " Alert E-mail" in FG60D (I can see it in FWF60C) PS. 1. IMHO from security perspective logs outside company is not too good idea. I know - encrypted... Fortinet ... etc. but still it goes to stranger.

Dominik Weglarz, IT System Engineer

Dominik Weglarz, IT System Engineer
Phill_Proud

IMHO from security perspective logs outside company is not too good idea. I know - encrypted... Fortinet ... etc. but still it goes to stranger.
Agreed, but they do offer FortiAnalyzer instead. Depends on the number of devices you have, but if it' s 10+ chances are you probably want this. I also find sflow + a flow analyzer quite useful.
AtiT
Valued Contributor

Hi dominikw, regarding your issue with: " I don' t have " Security Log" sectiona at all..." Maybe you need to generate some log. Log off from the GUI and log ON again. But you probably did that. Another thing - when you enable the extended-utm-log under the profile, also check the other settings, see below: THP_LAB # config webfilter profile THP_LAB (profile) # edit TEST_WF THP_LAB (TEST_WF) # get ... extended-utm-log : disable web-filter-sdns-action: redirect web-filter-sdns-portal: 0.0.0.0 ... After you enable the extended-utm-log: ... extended-utm-log : enable log-all-url : disable web-content-log : disable web-filter-activex-log: disable web-filter-command-block-log: disable web-filter-cookie-log: disable web-filter-applet-log: disable web-filter-jscript-log: disable web-filter-js-log : disable web-filter-vbs-log : disable web-filter-unknown-log: disable web-filter-referer-log: disable web-filter-cookie-removal-log: disable web-filter-sdns-action: redirect web-filter-sdns-portal: 0.0.0.0 web-url-log : disable web-invalid-domain-log: disable web-ftgd-err-log : disable web-ftgd-quota-usage: disable ... you can see that all the " extended" settings are disabled. You have to choose what you want to see in the logs. This is the same for all other profiles like antivirus, etc...

AtiT

AtiT
dominikw
New Contributor II

Well - next problems ... If I enable AV (proxy or flow) in policy I cannot download exe and msi files from ultravnc . I found and enabled Comfort Clients options (default profile) but it doesn' t help. Is this an exception or I should expect more " download problems" ?

Dominik Weglarz, IT System Engineer

Dominik Weglarz, IT System Engineer
Labels
Top Kudoed Authors