Hot!Fortigate with VDOMS forwarding logs to FortiAnalyzer

Author
n00b
New Member
  • Total Posts : 11
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/07/29 19:44:28
  • Status: offline
2016/05/15 09:25:42 (permalink) 5.2
0

Fortigate with VDOMS forwarding logs to FortiAnalyzer

May I ask as to what is the best practice when the Fortigate has 3 VDOMS including the root VDOM and the logs are forwarded to FortiAnalyzer?
Right now, every VDOM is allocated 1 port on the FortiAnalyzer so that every VDOM can forward logs to the FortiAnalyzer.
The Fortigate has 3 VDOMs including the root VDOM.
The FortiAnalyzer 200D has only 4 ports.
Is there a way so that 1 Fortigate device however how many number of VDOMs it has can forward logs to the FortiAnalyzer using one port only on the FortiAnalyzer?
post edited by n00b - 2016/05/15 09:29:11
#1
MrSinners
Bronze Member
  • Total Posts : 51
  • Scores: 10
  • Reward points: 0
  • Joined: 2014/03/05 09:22:42
  • Status: offline
Re: Fortigate with VDOMS forwarding logs to FortiAnalyzer 2016/05/15 12:01:32 (permalink)
0
Hiya,
 
You may have misunderstood or configured something wrongly. Normally you configure just 1 interface on the FortiAnalyzer, then on the FortiGate you configure logging to the FortiAnalyzer globally (Global > Log Config > Log settings) which is then applied for every VDOM. This ensures that all logging from the FortiGate, including those of alle VDOM's, are sent out from the management VDOM (normally root)  to the FortiAnalyzer. The FortiAnalyzer is capable of seeing which VDOM's are present on the FortiGate, and the log view can be split out over VDOM's using Log Arrays for easier reading.
#2
n00b
New Member
  • Total Posts : 11
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/07/29 19:44:28
  • Status: offline
Re: Fortigate with VDOMS forwarding logs to FortiAnalyzer 2016/05/15 18:29:16 (permalink)
0
Yes, I also think that I got it wrong. I was expecting that from FortiGate Global, logs from all the VDOMs are forwarded to the FortiAnalyzer.
However, when an interface in the FortiGate Global was given an IP address that is in the same subnet as the FortiAnalyzer interface, ping is not possible.
Example:
FortiGate>Global>Network>Interfaces>port1>192.168.1.99/24
FortiAnalyzer>System Settings>Network>port1>192.168.1.100/24
 
FortiGate>Global>CLI>ping 192.168.1.100
result: cannot ping
 
Do I ping from the Global?
Or do I ping from the root VDOM?
 
Thanks for in advance for any feedback.
 
#3
MrSinners
Bronze Member
  • Total Posts : 51
  • Scores: 10
  • Reward points: 0
  • Joined: 2014/03/05 09:22:42
  • Status: offline
Re: Fortigate with VDOMS forwarding logs to FortiAnalyzer 2016/05/16 03:12:48 (permalink)
0
Ping can only be used within VDOM's, in this case "execute ping 192.168.1.100" within VDOM root. Make sure that:
- VDOM root is indeed marked as the management VDOM (Global > VDOM >VDOM and then verify the upper right value after "Switch Management")
- The trusted hosts of the configured administrators on the FortiAnalyzer and/or FortiGate do not block this ping request. (e.g. the trusted hosts should contain 192.168.1.0/24 or 0.0.0.0/0.0.0.0)
- PING is allowed and enabled on the interface.
 
Otherwise there is a layer 2 issue, as ping should work especially within the same subnet/vlan. (check cables and switch configurations) You can also try and directly connect your laptop to either interface and ping the FortiGate/FortiAnalyzer as a way of checking where the fault is.
 
#4
n00b
New Member
  • Total Posts : 11
  • Scores: 0
  • Reward points: 0
  • Joined: 2015/07/29 19:44:28
  • Status: offline
Re: Fortigate with VDOMS forwarding logs to FortiAnalyzer 2016/05/21 00:30:35 (permalink)
0
Thanks very much Mr Sinners. This helped.
#5
taiwokaffo
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/08/06 09:48:42
  • Status: offline
Re: Fortigate with VDOMS forwarding logs to FortiAnalyzer 2020/08/07 03:41:42 (permalink)
0
Hello i have a similar issue here, the analyzers sees other VDOMs and it is not seeing others, and i have check that the IP address of the analyzer has been set globally on VDOMs. I will like to know how i can manually make the VDOMs that are red on the FAZ come green. Am really seeking for help on this.
 
Thanks
#6
Jump to:
© 2020 APG vNext Commercial Version 5.5