Mike Cook Fortigate 100E Firmware v5.6.2 build1486 (GA
ORIGINAL: mtcook01 Well I take that back, now that I am actually on the computer (not remotely logged in) I can work with wireshark a bit more. I do see that syslog messages are being sent to the host. Neither IView or Kiwi seem to be able to decipher then. I changed the serial and IPs below, but there is the stream. 142 8.775821000 10.1.10.1 10.1.10.45 Syslog 526 LOCAL7.NOTICE: date=2013-08-13 time=12:04:25 devname=ESC-Primary devid=FG100C3G09690876 logid=0000000013 type=traffic subtype=forward level=notice vd=root srcip=1921.2.109 srcport=62133 srcintf=" ESCMain" dstip=173.194.74.120 dstport=80 dstintf=" wan1" sessionid=6413 status=close policyid=3 dstcountry=" United States" srccountry=" Reserved" trandisp=snat transip=23.31.163.177 transport=62133 service=HTTP proto=6 applist=" block-p2p" duration=301 sentbyte=2713 rcvdbyte=1598 sentpkt=10 rcvdpkt=14That looks more like browser traffic to me....
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
That looks more like browser traffic to me....I think Mike is indicating that entire log event is the data stream itself to the syslog server.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
PCNSE
NSE
StrongSwan
Mike Cook Fortigate 100E Firmware v5.6.2 build1486 (GA
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Mike Cook Fortigate 100E Firmware v5.6.2 build1486 (GA
set forward-traffic enable set local-traffic enable set netscan enable set voip enable set analytics enable set discovery enable set dlp-docsource enable set email-log-google enable set multicast-traffic enable set suspicious enable set switching-protocols enable set vulnerability enable set web-filter-command-block enableDiff (works on 100A)...
set explicit-proxy-traffic enable set failed-connection enable unset override set wanopt-traffic enable set webcache-traffic enable set allowed enable set extended-traffic-log enable set violation enablePersonally, if I had a spare 110C unit or can afford some down time, I' d just make a backup of the config and perform " exec factoryreset" on the 110C (or spare unit) then set up syslogd logging on a " clean" config. If that works then save that config and restore the old one. Compare the diff between the two configs.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Mike Cook Fortigate 100E Firmware v5.6.2 build1486 (GA
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.