Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chrbar
New Contributor

"start" action logs on mgmt1 port ?

Hello, We use two FortiGate 3700D (HA cluster) running FortiOS 5.2.1 build0618, managed from FortiManager v5.2.1-build0662. We checked logs on mgmt1 port into FortiView (and into other log file analyzer), and we noticed two things about these logs: - we don't see logs from "start" action (we see deny and close action logs only), - all "close" action logs have the Policy ID "0" ("deny" too). Do you know why we don't see logs from "start" action?

 

Note: "Log All Sessions" and "Generate Logs when Session Starts" into "Logging Options" are activated in all rules. Regards, Chris

 

1 REPLY 1
chrbar
New Contributor

Hi! Does someone have any idea about this question? Thanks, Chris

 

chrbar wrote:

Hello, We use two FortiGate 3700D (HA cluster) running FortiOS 5.2.1 build0618, managed from FortiManager v5.2.1-build0662. We checked logs on mgmt1 port into FortiView (and into other log file analyzer), and we noticed two things about these logs: - we don't see logs from "start" action (we see deny and close action logs only), - all "close" action logs have the Policy ID "0" ("deny" too). Do you know why we don't see logs from "start" action?

 

Note: "Log All Sessions" and "Generate Logs when Session Starts" into "Logging Options" are activated in all rules. Regards, Chris

 

Labels
Top Kudoed Authors