Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
thedom
New Contributor

issue logging udp traffic

Firstly: I have a faz100B Firmware Version v4.0,build0218 (MR2 Patch 2) I have a fortigate310b on latest fw too! Im having problems with the faz logging traffic(significant traffic 500gb excess) that is udp traffic on ports higher than 33000. It doesnt seem to be recording in my faz. When i log into my fortigate i can see the traffic in the sessions widget no problems there but in my faz it is not recorded. everything else seems to be logged ok. The policy in my fortgate is being set to log accepted traffic. So does anyone have any ideas or am i missing something. My issue is that most of the bandwidth we consume comes from this type of traffic not being captured so i am having a hard time with management trying to show them we need more bandwidth etc. any help would be appreciated thanks
6 REPLIES 6
billp
Contributor

Is the FAZ100B fast enough to grab all the logs from a 310B generating 500GB of traffic? When I was looking at a 310B, they would not sell me a FAZ100B because it wasn' t compatible with the traffic load. I thought the 100B was set up to not accept connections from a 310B-class firewall, but never had a chance to try it. I believe the new FAZ100C appliance will work.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
thedom
New Contributor

Hi Bill Im not sure but the faz100b is certainly capturing everything else by the look of my reports.. anybody else have any ideas ?
Jan_Scholten
Contributor

In generall the FGT only logs traffic when the session is terminated (as a log entry contains duration, and transferred bytes) which can seriously delay logging of long living sessions. Solution in this case:
config log fortianalyzer filter 
 set other-traffic enable
Which will log the start of sessions as well. But the other statments about a overwhelmed FAZ maybe true as well.
thedom

thanks for the suggestion, i will make the change and see how we go... In regards to the faz being overwelmed what model woukld overcome this potential issue ?
ede_pfau
SuperUser
SuperUser

We use a FAZ 400B with a A-P cluster of 310Bs. CPU usage while logging only is low (1-5%), with traffic logs active. The only drawback is the slow performance while generating reports. Some take 15-20 minutes. (Even if the only line in the final report reads " No data available." :-) If you say that you have >500 GB traffic across the FG-310B, that doesn' t relate to the performance needed for the FAZ. Depends on what you log, to what extent and how many reports you' ll create per day.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
thedom

we basically download audio/video(its legit people not pirated =) ) which we use for production, so typically in a month we would download anywhere between 500-1000gb a month. Now this application we use for the high speed content delivery(http://www.asperasoft.com/) uses udp to send data on ports above 33000. now you would think after a month i would have alot to report but unfortunately it seems like the traffic information for this application doesnt hit my faz at all. i have even created a report to show only items from the policy on my firewall which this application uses for the delivery...i suppose thats what lead me to suspect perhaps the higher udp ports do not get recorded or its a product limitation.. in terms of daily data flow for this application this would be typically around 20gb-100gb so i wouldnt think the faz should not be overwhlmed and looking at the cpu usage on the fortgiate and the faz when doing a test transfer using this software i see no signs of stress or high usage. thanks for your thoughts
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors