Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dlodovici
New Contributor

Forward traffic log question

Hi,

 

I have a FortiGate 3040B (v5.2) connected via an IPsec VPN tunnel to a FortiGate 60D (v5.4) installed on a remote site.

On the FortiGate 3040B, in the "Traffic log" -> "Forword Traffic", I don't have any log about DNS. If I put the IP address of the DHCP and DNS server in the Source IP and the IP address of a PC behind the Fortigate 60D in the Destination address, I look only DHCP packets.

 

Someone could explain me why ?

 

Thank you

6 REPLIES 6
vivianwu_FTNT

do you mean no dns related traffic log if put filter on source ip address using both dhcp and dns servers ip? 

 

did you filter on GUI or cli? 

 

 

dlodovici

Yes, the DHCP and DNS services are on the same server, so the same IP.

On the FortiGate 3040B I can see DHCP packets in both directions, but DNS packets only in ingress.

 

I filter in GUI and I have the same results with a syslog server

 

 

Thank you

MikePruett

Are you only logging UTM events on your policies or are you logging all sessions?

Mike Pruett Fortinet GURU | Fortinet Training Videos
dlodovici

I Mike,

 

all sessions

MikePruett

Are you able to see the traffic (DNS etc) if you do a packet debug? (diag deb flows and traces)

Mike Pruett Fortinet GURU | Fortinet Training Videos
dlodovici

I Mike,

 

yes, with the command diagnose sniffer packet I see DNS traffic.

So, you think it is a GUI problem ?

 

Labels
Top Kudoed Authors