Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
thomasevig
New Contributor

syslog server configured yet syslog server not getting any logs

hello,

 

i've configured syslog server on of our clients' vdom,

including the configuration -

 

config log syslogd override-setting <---     set override enable     set status enable     set server "CUSTOMER EXTERNAL SERVER IP (OMMITED for security measurments) "     set reliable enable     set port 601     set facility syslog <---     set source-ip "OUR VDOM EXTERNAL IP ( OMMITED for security measurments) "     set format default end config log syslogd override-filter <---     set severity notification     set forward-traffic enable     set local-traffic enable     set multicast-traffic enable     set sniffer-traffic enable     set anomaly enable     set voip enable     set dns enable     set filter ''     set filter-type include end

 

 

 

 

diagnose sniffer packet any "host ***** and port 601" 4 0 interfaces=[any] filters=[host ***** and port 601] 0.905981 ***-WAN out *****.10568 -> ******.601: fin 2063666531 ack 1219845830 0.905983 WAN out ommited.10568 -> *****.601: fin 2063666531 ack 1219845830 0.905984 port35 out ommited.10568 -> *****.601: fin 2063666531 ack 1219845830 0.906015 ***-WAN out ommited.6695 -> *****.601: syn 3437827387 0.906016 WAN out ommited.6695 -> *****.601: syn 3437827387 0.906017 port35 out ommited.6695 -> *****.601: syn 3437827387

 

 

according to the results and configuration , all configured properly yet the server doesn't receive any logs from the fortigate.

 

thanks in advance ,

 

Thomas .

 

1 Solution
Toshi_Esumi
SuperUser
SuperUser

Did you configured syslog server at global? We never tried this but it might be an issue if you don't have it there before you can override it at a vdom. Hopefully somebody else has experiences.

View solution in original post

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

Did you configured syslog server at global? We never tried this but it might be an issue if you don't have it there before you can override it at a vdom. Hopefully somebody else has experiences.

emnoc
Esteemed Contributor III

Yes that cfg is good. So the  dump show syn/ack and fin so what is configured at whatever syslogd server and what does diag debug flow show  ?

 

Yes any  thing done at the override override the global.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
thomasevig

 hi,

 

i haven't configured on the global vdom ,

it has been configured on the Clients' Vdom.

 

 i think that configuring it on global would result

in all of our customers having these settings. (there are many other clients on the unit)

emnoc
Esteemed Contributor III

Yes that's correct configure it in the customer-vdom and run diag-debug-flow ensure it  traffic is not being blocked by any other  vdom or rule

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors