12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FortiGuard Analysis Service<br />

Log&Report<br />

You can customize the level that the <strong>FortiGate</strong> unit logs these events at as well as<br />

where the <strong>FortiGate</strong> unit stores the logs. The level these events are logged at, or<br />

the severity level, is defined when configuring the logging location. There are six<br />

severity levels to choose from. See “Log severity levels” on page 471 for more<br />

information.<br />

For better log storage and retrieval, the <strong>FortiGate</strong> unit can send log messages to a<br />

FortiAnalyzer unit. FortiAnalyzer units are network appliances that provide<br />

integrated log collection, analysis tools and data storage. Detailed log reports<br />

provide historical as well as current analysis of network and email activity. Detailed<br />

log reports also help identify security issues, reducing network misuse and abuse.<br />

The <strong>FortiGate</strong> unit can send all log message types, as well as quarantine files, to<br />

a FortiAnalyzer unit for storage. The FortiAnalyzer unit can upload log files to an<br />

FTP server for archival purposes. See “Logging to a FortiAnalyzer unit” on<br />

page 472 for details on configuring the <strong>FortiGate</strong> unit to send log messages to a<br />

FortiAnalyzer unit.<br />

The <strong>FortiGate</strong> unit can send log messages to either a Syslog server or<br />

WebTrends server for storage and archival purposes. You can also configure the<br />

<strong>FortiGate</strong> unit to send log messages to its hard disk, if available. Configuring the<br />

<strong>FortiGate</strong> unit to send log messages to the hard disk is only available in the CLI.<br />

See the <strong>FortiGate</strong> CLI Reference for configuring logging to the hard disk.<br />

The <strong>FortiGate</strong> unit enables you to view log messages available in memory, on a<br />

FortiAnalyzer unit running firmware version 3.0 or higher, including the hard disk if<br />

available. Customizable filters enable you to easily locate specific information<br />

within the log files.<br />

See the <strong>FortiGate</strong> Log Message Reference for details and descriptions of log<br />

messages and formats.<br />

FortiGuard Analysis Service<br />

FortiGuard Analysis Service is a subscription-based service that provides logging<br />

and reporting solutions for <strong>FortiGate</strong>-100A units and lower. The FortiGuard<br />

Analysis Service is available on <strong>FortiGate</strong>-100A units and lower running FortiOS<br />

3.0MR4 and higher.<br />

The FortiGuard Analysis network is made up of two types of servers, the primary<br />

analysis server and the secondary analysis server. The primary analysis server<br />

stores logs generated from the <strong>FortiGate</strong> unit. The secondary analysis server<br />

provides redundancy, ensuring log data is available at all times. There are several<br />

secondary analysis servers available for redundancy for each <strong>FortiGate</strong> unit. The<br />

network also includes the main analysis server, which is responsible for<br />

monitoring and maintaining the primary and secondary analysis servers.<br />

When the <strong>FortiGate</strong> unit connects for the first time to the FortiGuard Analysis<br />

network, the <strong>FortiGate</strong> unit retrieves its assigned primary analysis server, contract<br />

term, and storage space quota from the main analysis server. The main analysis<br />

server contains this information so it can maintain and monitor the status of each<br />

of the servers.<br />

After configuring logging to the assigned primary analysis server, the <strong>FortiGate</strong><br />

unit begins logging to that primary analysis server. The <strong>FortiGate</strong> unit sends<br />

encrypted logs to the primary analysis server using TCP port 514. The connection<br />

to the main analysis server is secured by SSL using port 443.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

470 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!