A real-life situation
An auditor asks: "Who connected to the finance server last month, and who changed the firewall rules on the 3rd?" Another day a manager wants an email whenever a VPN tunnel to the branch goes down. Each answer depends on the FortiGate having logged the right things to a place where they still exist.
Log types
| Type | Subtypes | Answers |
|---|---|---|
| Traffic | Forward (through), local (to/from the FortiGate), sniffer | Who talked to whom, by which policy, how much |
| Event | System, user, VPN, router, HA, SD-WAN, endpoint… | Who logged in, what changed, which tunnel dropped |
| Security | AntiVirus, web filter, DNS filter, application control, IPS… | What was detected and blocked |
Traffic logging is set per policy (logtraffic: all sessions, security events only, or off). Event logging is set globally under Log & Report › Log Settings.
Where logs go
config log fortianalyzer setting
set status enable
set server "10.0.1.30"
set upload-option realtime
end
config log syslogd setting
set status enable
set server "10.0.1.40"
set mode udp
set port 514
endFortiAnalyzer receives logs in real time and gives search, reports and long retention; the FortiGate must be authorised on the FortiAnalyzer. A syslog server (or SIEM) can receive a copy at the same time. FortiGate Cloud is the hosted option for small sites.
Reading logs
Forward Traffic (filter: destination 10.0.2.10, last 7 days)
| Date/Time | Source | User | Destination | Service | Policy | Result |
|---|---|---|---|---|---|---|
| 10-10 16:41 | 10.0.1.23 | alice | 10.0.2.10 | HTTPS | 8 | Accept (2.1 MB) |
| 10-10 14:02 | 10.0.1.40 | carol | 10.0.2.10 | HTTPS | 4 | Deny: policy violation |
| 10-09 09:15 | 198.51.100.77 | 10.0.2.10 | HTTPS | 6 | Accept (48 kB) |
On the CLI, the same search:
execute log filter category traffic
execute log filter field dstip 10.0.2.10
execute log displayFilters select the log category and fields; display prints the matching entries (from the device's own storage). execute log filter reset clears the filters.
Watching it live
- Dashboards and FortiView: top sources, destinations, applications, threats and policies, with drill-down to the logs.
- SNMP: CPU, memory, sessions and interface counters for your monitoring system; traps for events such as HA failover.
- Automation stitches: a trigger, such as an IPsec tunnel going down, an HA failover or an admin login failure, linked to an action, such as an email, a webhook or a CLI script.
FGT1 # get system performance status CPU states: 3% user 1% system 0% nice 96% idle 0% iowait 0% irq 0% softirq CPU0 states: 3% user 1% system 0% nice 96% idle 0% iowait 0% irq 0% softirq Memory: 2055456k total, 851288k used (41.4%), ... Average network usage: 41250 / 39870 kbps in 1 minute, ... Average sessions: 1834 sessions in 1 minute, ... Uptime: 12 days, 4 hours, 31 minutes
Why it works this way
A firewall makes thousands of decisions a minute; logs are the only record of them. Keeping logs off the device protects them from being lost on reboot or erased by an attacker who gets in, and a central collector lets you search across many FortiGates at once.
Common mistakes
- Relying on memory logging on a small model, then finding nothing after a reboot.
- Logging off on the implicit deny and no logged deny-all policy, so blocked traffic leaves no trace.
- Wrong time or time zone, making logs impossible to correlate with other systems (set NTP).
- Never testing alerts until the day they were needed.
Key takeaways
- Logs are traffic, event and security; traffic logging is chosen per policy.
- Send logs off the device to FortiAnalyzer, FortiGate Cloud or syslog.
- Filter in Log & Report or with execute log filter and execute log display.
- Use FortiView, SNMP and automation stitches to watch and alert.
Check yourself
Which log type shows who changed a firewall policy?
You need an email whenever the VPN to the branch goes down. What do you configure?
A small FortiGate without a disk has no logs from before last night's reboot. Why?