Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
config log memory setting set status enable endPlease check the (many) options in ' config log memory filter' to enable the different log sources. You get a more complete picture of these commands from the ' CLI Reference' on docs.fortinet.com. Actually, there are WebGUI controls for this but they are disabled by default. One hint though: your FGT is running 5.0.0; get the latest patch release 5.0.6 (v5 MR 0 patch 6) from support.fortinet.com and upgrade, it' s worth it in terms of stability and resource consumption.
Ahead of the Threat. FCNSA v5 / FCNSP v5
Fortigate 1000C / 1000D / 1500D
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
: Quit menu and continue to boot with default firmware.: Display this list of options. !!!!!!!!!!!!!!ATTENTION YOU WILL LOST EVERY CONFIGURATION!!!!!!!!!!!!!!! Format with " F" your device or choose " Format boot device" Enter G,F,Q,or H: F All data will be erased,continue:[Y/N]? Formatting boot device... ............... Format boot device completed. After that you use a TFTP Server on your laptop with a IP configured. The IP and you subnet you are using on your laptop must fit the TFTP configuration on the FortiGate. A 60D has a different Bios Menü which means choose: Review TFTP Parameters If you configured your laptop with the TFTP Server running (If you do not have one use http://www.solarwinds.com/products/freetools/free_TFTP_server.aspx) you can choose: : Initiate TFTP firmware transfer or : Get firmware image from TFTP server Look to the menü on the screen because it is indicating to which port you have to connect your cable RJ-45 which connects from laptop to the FortiGate. As soon as you see following firmware is transfered: Enter firmware image file name [image.out]: ############ Total 13547047 bytes data downloaded. Verifying the integrity of the firmware image. Total 28000kB unzipped. If the firmware is transfered following will be shown: Save as Default firmware/Run image without saving:[Choose " D" for default to be booted] It take some time but at least you will see the Login. Login to the Devices with admin no password. No you have to format your Disk because a 60D HAS A DISK. Acutally it is a Flash Disk. Use to format: # execute formatlogdisk Answer yes and a reboot will be done. After you come up again use following: # get system status You will see a position with " Disk available" ! Configure now " global" log function with: (setting) # get brief-traffic-format: disable daemon-log : disable fwpolicy-implicit-log: enable fwpolicy6-implicit-log: disable gui-location : disk local-in-allow : disable local-in-deny : enable local-out : disable log-invalid-packet : disable log-user-in-upper : disable neighbor-event : disable resolve-apps : enable resolve-hosts : enable resolve-ip : disable resolve-port : enable user-anonymize : disable (setting) # if you like to configure log to disk set at least: # set gui-location disk # end After that check every log possibility to be set to " disable" except for disk which means: # config log fortiguard setting # set status disable # end # config log memory setting # set status disable # end # config log syslogd setting # set status disable # end # config log fortianalyzersetting # set status disable # end Normal all is set to " disable" . Activate now log to disk: # config log disk setting # set status enable # end Now you can configure on a Policy Rule in the Gui " Log all sessions" . be careful to log to the disk. FortiGate is using Flash as Disk and heafy log to disk is not really recommended. Flash does not really like heavy writting processes etc. Recommended -if possible- is acutally " memory" logging. This means 10% of the Memory is used to log. If 10% is full the log space is deleted and overwritten etc. Have fun Andrea
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1073 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.