Page 2 - Trademarks; For technical support, please visit
© Copyright 2005 Fortinet Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced,transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical orotherwise, for any purpose, without prior written pe...
Page 3 - Table of Contents
Contents FortiLog Administration Guide 05-16000-0082-20050115 3 Table of Contents Introduction ............................................................................................................ 7 Operational Modes................................................................................
Page 7 - FortiLog Administration Guide Version 1.6; Introduction; FortiLog units operate in one of two modes:
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 7 Introduction FortiLog units are network appliances that provide integrated log collection, analysis tools and data storage. Detailed log reports provide historical as well as current analysis of network ...
Page 8 - Operational Modes; Active Mode; Figure 2: FortiLog unit in Active mode
8 05-16000-0082-20050115 Fortinet Inc. Operational Modes Introduction Operational Modes The FortiLog device can operate in two modes: Active mode or Passive mode. The web-based interface provides an interface that reflects each models’ functionality. Active Mode Active mode is the default mode for t...
Page 9 - Figure 3: FortiLog Active mode network architecture; Passive Mode; Figure 4: FortiLog unit in Passive mode
Introduction Operational Modes FortiLog Administration Guide 05-16000-0082-20050115 9 Figure 3: FortiLog Active mode network architecture Passive Mode Passive mode enables you to use the FortiLog unit solely as a Network Attached Server (NAS) storage device. The collection of device log files and th...
Page 10 - About this guide
10 05-16000-0082-20050115 Fortinet Inc. About this guide Introduction About this guide This document describes how to set up and configure the FortiLog unit. The configuration and features of the FortiLog unit are similar in either mode. Section titles indicate where the features or configuration di...
Page 11 - Related documentation; FortiGate documentation; Provides a context-sensitive and searchable version of the
Introduction Related documentation FortiLog Administration Guide 05-16000-0082-20050115 11 Related documentation Additional information about Fortinet products is available from the following related documentation. FortiGate documentation Information about FortiGate products is available from the fo...
Page 12 - FortiManager documentation
12 05-16000-0082-20050115 Fortinet Inc. Related documentation Introduction FortiManager documentation • FortiManager QuickStart Guide Explains how to install the FortiManager Console, set up the FortiManager Server, and configure basic settings. • FortiManager System Administration Guide Describes h...
Page 13 - Customer service and technical support
Introduction Customer service and technical support FortiLog Administration Guide 05-16000-0082-20050115 13 Customer service and technical support For antivirus and attack definition updates, firmware updates, updated product documentation, technical support information, and other resources, please ...
Page 15 - Setting up the FortiLog unit; This chapter includes:; Checking the package contents
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 15 Setting up the FortiLog unit This chapter includes: • Checking the package contents • Hardware specifications • Planning the installation • Connecting the FortiLog unit • Configuring the FortiLog unit C...
Page 16 - Figure 5: FortiLog front and back diagrams; Hardware specifications
16 05-16000-0082-20050115 Fortinet Inc. Checking the package contents Setting up the FortiLog unit Figure 5: FortiLog front and back diagrams Hardware specifications Dimensions • FortiLog-100: 38 x 17 x 31 cm• FortiLog-400: 54 x 33 x 44 cm• FortiLog-800: 78 x 65 x 25 cm Weight • FortiLog-100: 2.5 kg...
Page 17 - Power requirements; operation of the equipment is not compromised.; Mechanical loading; Planning the installation
Setting up the FortiLog unit Planning the installation FortiLog Administration Guide 05-16000-0082-20050115 17 Power requirements • FortiLog-100 • AC input voltage: 100 to 240 VAC• AC input current: 1.0 A• Frequency: 47 to 63 Hz • FortiLog-400 and 800 • AC input voltage: 115 to 230 VAC• AC input cur...
Page 18 - Figure 6: FortiLog connection option; Connecting the FortiLog unit; To connect the FortiLog unit to the network; Place the unit on a stable surface.; Management PC; FortiLog unit
18 05-16000-0082-20050115 Fortinet Inc. Connecting the FortiLog unit Setting up the FortiLog unit Figure 6: FortiLog connection option Connecting the FortiLog unit You can install the FortiLog unit as a free-standing appliance on any stable surface. You can mount the FortiLog-800 unit in a standard ...
Page 19 - Configuring the FortiLog unit; Using the web-based manager; To connect to the web-based manager; Table 2: Factory defaults; LAN
Setting up the FortiLog unit Configuring the FortiLog unit FortiLog Administration Guide 05-16000-0082-20050115 19 Configuring the FortiLog unit Use the web-based manager or the Command Line Interface (CLI) to configure the FortiLog unit IP address, netmask, DNS server IP address, and default gatewa...
Page 20 - To configure the FortiLog unit using the web-based manager; Using the command line interface; To connect to the FortiLog-800 unit; To configure the FortiLog unit using the CLI; get system interface
20 05-16000-0082-20050115 Fortinet Inc. Configuring the FortiLog unit Setting up the FortiLog unit 6 Type admin in the Name field and select Login. After connecting to the Web-based manager, you can configure the FortiLog unit IP address, DNS server IP address, and default gateway to connect the For...
Page 21 - Set the primary DNS server IP address:; Using the front panel buttons and LCD
Setting up the FortiLog unit Configuring the FortiLog unit FortiLog Administration Guide 05-16000-0082-20050115 21 3 Set the primary DNS server IP address: set system dns primary <IP_address> 4 Optionally set the secondary DNS server IP address: set system dns secondary <IP_address> 5 Se...
Page 23 - Connecting to the FortiLog Unit; Sending device logs to the FortiLog unit; Configuring FortiGate unit running FortiOS 2.8; Log on to the FortiGate unit.
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 23 Connecting to the FortiLog Unit In order for FortiLog to receive log files, you need to configure the FortiGate, FortiMail or syslog devices to send log files to the FortiLog unit. You also need to conf...
Page 24 - Enter the IP address of the FortiLog unit.; Configuring FortiGate devices running FortiOS 2.5; Go to
24 05-16000-0082-20050115 Fortinet Inc. Sending device logs to the FortiLog unit Connecting to the FortiLog Unit Figure 7: FortiGate 2.8 log settings 5 Enter the IP address of the FortiLog unit. 6 Set the level that the FortiGate unit logs messages to the FortiLog unit.The FortiGate unit logs all me...
Page 25 - Configuring FortiMail devices; Log Setting; “Log policy” on page 45
Connecting to the FortiLog Unit Sending device logs to the FortiLog unit FortiLog Administration Guide 05-16000-0082-20050115 25 Figure 8: FortiGate 2.5 Log settings 2 Select Log to Remote Host to send the logs to a syslog server. 3 Enter the IP address of the FortiLog unit. 4 Enter the port number ...
Page 26 - Adding a device; To add a device; For a FortiGate device, go to
26 05-16000-0082-20050115 Fortinet Inc. Configuring the FortiLog unit Connecting to the FortiLog Unit Configuring the FortiLog unit When you configure a device to send logs to the FortiLog unit, an entry for the device appears automatically in the Unregistered Devices tab. Adding a device The Device...
Page 27 - “Creating Device Groups” on page 28; Defining device port interfaces
Connecting to the FortiLog Unit Configuring the FortiLog unit FortiLog Administration Guide 05-16000-0082-20050115 27 3 Enter a device name. For a FortiGate device, this is the same entry as entered as the Local ID set in the Log&Config settings for FortiLog. For example, FGT-500A . 4 Select a g...
Page 28 - Creating Device Groups; To create a device group; Table 3: Log report traffic direction identification
28 05-16000-0082-20050115 Fortinet Inc. Configuring the FortiLog unit Connecting to the FortiLog Unit You can classify the device interfaces as one of None, LAN, WAN or DMZ to match the type of traffic the interface will process. When the FortiLog unit generates the traffic log report, the FortiLog ...
Page 29 - Managing the FortiLog unit; Status
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 29 Managing the FortiLog unit Using the FortiLog system settings, you can view the operating status of the FortiLog unit and configure the FortiLog unit for your network. You can also use system settings t...
Page 31 - Changing the FortiLog host name; To change the FortiLog unit host name; Changing operating modes; “Operational Modes” on page 8; To change the operating mode in the web-based manager
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 31 Changing the FortiLog host name The FortiLog host name appears on the Status page and in the FortiLog CLI prompt. To change the FortiLog unit host name 1 Go to System > Status > Status . 2 Select Change. ...
Page 32 - Viewing system resources information; “Backing up system settings” on page 39; To change the firmware using the web-based manager; Copy the firmware image file to your management computer.
32 05-16000-0082-20050115 Fortinet Inc. Status Managing the FortiLog unit Viewing system resources information On the Status page, you can view the CPU, memory and hard disk usage information and the session information. By selecting the History link under System Resources, you can also view the sta...
Page 33 - To change the firmware using the CLI; execute backup config; Installing firmware from a system reboot
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 33 To change the firmware using the CLI Use the following procedure to upgrade the FortiLog unit to a newer firmware version or revert to a previous firmware version. To use the following procedure you must have a...
Page 34 - To install firmware from a system reboot; Make sure that the TFTP server is running.; execute reboot
34 05-16000-0082-20050115 Fortinet Inc. Status Managing the FortiLog unit To perform this procedure you need to install a TFTP server that you can connect to from the FortiLog unit LAN port. The TFTP server should be on the same subnet as the LAN port. Before beginning this procedure you can back up...
Page 35 - The following message appears:; Testing a new firmware image; To test a new firmware image before installing it; Make sure the TFTP server is running.
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 35 The following message appears: Enter File Name [image.out]: 11 Enter the firmware image filename and press Enter.The TFTP server uploads the firmware image file to the FortiLog unit and a message similar to the...
Page 36 - Immediately press any key to interrupt the system startup.; Installing a backup firmware image
36 05-16000-0082-20050115 Fortinet Inc. Status Managing the FortiLog unit 7 Immediately press any key to interrupt the system startup. If you successfully interrupt the startup process, the following message appears: [G]: Get firmware image from TFTP server.[F]: Format boot device.[Q]: Quit menu and...
Page 37 - To install a backup firmware image
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 37 To install a backup firmware image 1 For all three FortiLog models, use a terminal emulation software to access the unit’s CLI.For the FortiLog-800 unit, you can also access the unit’s CLI by connecting the nul...
Page 38 - Switching to a backup firmware image; “Switching to the default firmware image” on page 38; To switch to the backup firmware image; Enter the following command to restart the FortiLog unit:; Switching to the default firmware image
38 05-16000-0082-20050115 Fortinet Inc. Status Managing the FortiLog unit The FortiLog unit saves the backup firmware image and restarts. When the FortiLog unit restarts it is running the previously installed firmware version. Switching to a backup firmware image Use this procedure to switch the For...
Page 39 - To switch back to the default firmware image; Backing up system settings; To backup up system settings; Downlading the FortiLog debug log
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 39 To switch back to the default firmware image 1 For all three FortiLog models, use a terminal emulation software to access the unit’s CLI.For the FortiLog-800 unit, you can also access the unit’s CLI by connecti...
Page 40 - To download a FortiLog debug log; Restoring system settings; To restore system settings; Restore factory default system settings; To restore system settings to factory defaults; Restoring a FortiLog unit
40 05-16000-0082-20050115 Fortinet Inc. Status Managing the FortiLog unit To download a FortiLog debug log 1 Go to System > Status > Status . 2 For System Settings, select Backup. 3 Select download debug log. 4 Type a name and location for the file.The debug log file is backed up to the manage...
Page 41 - To upload the firmware image to the FortiLog unit; RAID; Go; Refresh; Create Date
Managing the FortiLog unit Status FortiLog Administration Guide 05-16000-0082-20050115 41 To upload the firmware image to the FortiLog unit 1 Make sure the TFTP server is running. 2 Copy the firmware image file to the root directory of the TFTP server. Ensure the file name is image.out . 3 Start the...
Page 42 - Config; Network; To configure the FortiLog network settings, go to
42 05-16000-0082-20050115 Fortinet Inc. Config Managing the FortiLog unit Config Use system config to configure the FortiLog network settings, RAID settings, log message settings, time settings, and other options. You can also add and remove FortiLog administrator accounts and change administrator p...
Page 44 - Log settings; . You can configure the
44 05-16000-0082-20050115 Fortinet Inc. Config Managing the FortiLog unit Log settings To configure the FortiLog unit to log locally or to send FortiLog log messages to a remote syslog server, go to System > Config > Log Settings . You can configure the log level and you can use config policy ...
Page 45 - Log policy
Managing the FortiLog unit Config FortiLog Administration Guide 05-16000-0082-20050115 45 Log policy Select Config Policy to configure the FortiLog unit to send event log messages to a local or remote syslog server. Enable Event Log to record management and activity events. Management events include...
Page 46 - Time; To change the FortiLog unit time, go to; Options; To change the FortiLog administration options, go to; Admin; To change the FortiLog administrator settings, go to; Language
46 05-16000-0082-20050115 Fortinet Inc. Config Managing the FortiLog unit Time To change the FortiLog unit time, go to System > Config > Time . For effective scheduling and logging, the FortiLog system time must be accurate. You can either manually set the FortiLog system time or you can confi...
Page 47 - Configure Administrator access
Managing the FortiLog unit Config FortiLog Administration Guide 05-16000-0082-20050115 47 Figure 19: Admin Configure Administrator access Configure administrative access to allow remote administration of the FortiLog unit. However, allowing remote administration could compromise the security of your...
Page 48 - To configure administrative access to the FortiLog unit; Administrator account levels; There are three administration account access levels:; Administrator options; Figure 20: Administrator options; Read Only; Administrator
48 05-16000-0082-20050115 Fortinet Inc. Config Managing the FortiLog unit To configure administrative access to the FortiLog unit 1 Go to System > Config > Admin . 2 Select the Administrative Access methods for the FortiLog unit. 3 Select Apply. Administrator account levels When the FortiLog u...
Page 49 - To add an administrator account; Changing the Administrator password; To change the admin account password; Device list
Managing the FortiLog unit Devices (Active mode) FortiLog Administration Guide 05-16000-0082-20050115 49 To add an administrator account 1 Go to System > Config > Admin . 2 Select New. 3 Enter a login name for the administrator account. 4 Enter and confirm a password for the administrator acco...
Page 50 - To add and manage devices connecting to the FortiLog unit, go to; Adding and registering a device; “Sending device logs to the FortiLog unit” on page 23; Editing device information; Figure 22: Editing a device
50 05-16000-0082-20050115 Fortinet Inc. Devices (Active mode) Managing the FortiLog unit Device list To add and manage devices connecting to the FortiLog unit, go to System > Devices . Figure 21: Device list Adding and registering a device Add FortiGate, FortiMail and Syslog devices to the FortiL...
Page 51 - To edit a device; Alert Email; Server; To set the mail server options go to
Managing the FortiLog unit Alert Email FortiLog Administration Guide 05-16000-0082-20050115 51 To edit a device 1 Go to System > Devices . 2 For the device you want to edit, select Edit. 3 Modify the device information and select an Interface Type for each interface, as required. 4 Select OK. Ale...
Page 52 - To set the email alert notification for the FortiLog unit, go to; Local; Figure 24: Local alert settings; Creating a new device alert; When you add a new device alert, you can set the following options.
52 05-16000-0082-20050115 Fortinet Inc. Alert Email Managing the FortiLog unit Local To set the email alert notification for the FortiLog unit, go to System > Alert Email > Local . Set the options when the FortiLog unit alerts an individual or group of individuals. Figure 24: Local alert setti...
Page 54 - To add a device alert; Alerts; Single Source Only
54 05-16000-0082-20050115 Fortinet Inc. Alerts Managing the FortiLog unit To add a device alert 1 Go to System > Alert Email > Device . 2 Select Create New. 3 Set the Alert email options as required. 4 Select Enable to set the FortiLog unit to send alert email messages for selected devices. 5 ...
Page 55 - Network Sharing; “Using the FortiLog unit as a NAS” on page 81; Defining IP aliases
Managing the FortiLog unit Network Sharing FortiLog Administration Guide 05-16000-0082-20050115 55 Figure 26: Device alert messages Network Sharing Use Network Sharing to configure the FortiLog unit to use file sharing (Windows workgroups or NFS) to view and share log reports and other files. You ca...
Page 56 - Figure 27: IP aliases; To set host alias names
56 05-16000-0082-20050115 Fortinet Inc. Defining IP aliases Managing the FortiLog unit Figure 27: IP aliases To set host alias names 1 Go to Reports > IP Aliases . 2 Select Create New. 3 Enter a name of the host, network or IP address range in the Alias text box. 4 Enter the IP address of the hos...
Page 57 - Reports; “Appendix A: Log Report Types” on page 113; Creating and generating a report; To create a report
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 57 Reports The FortiLog unit collates information collected from device log files and presents the information in tables and graphs. There are over 130 different reports, in 11 categories. The reports prov...
Page 58 - Configuring report parameters; Figure 28: Report parameter settings; To define report parameters
58 05-16000-0082-20050115 Fortinet Inc. Creating and generating a report Reports 3 Set the following:• “Configuring report parameters” on page 58 • “Configuring a report query” on page 59 • “Selecting the devices for the report” on page 60 • “Select filtering options” on page 61 • “Setting a report ...
Page 59 - Configuring a report query; Figure 29: Report query options; To set the report queries; Per device; “Defining IP
Reports Creating and generating a report FortiLog Administration Guide 05-16000-0082-20050115 59 5 Select Apply. Configuring a report query Select the specific information you need to generate a more concise report. Each report category includes a refined list of sub-categories that reports specific...
Page 60 - Creating a query profile; To create a query profile; Enter a name for the profile and select OK.; Selecting the devices for the report; Figure 30: Selecting devices; To select the devices
60 05-16000-0082-20050115 Fortinet Inc. Creating and generating a report Reports 4 Select the plus sign next to a category to expand and view the sub categories. 5 Select the content from the sub-categories to include in the reports. 6 Select Apply. Creating a query profile You can save the selectio...
Page 61 - Select the group or individual devices to use in the report.; Creating a device profile; To create a device profile; Select filtering options; Figure 31: Filter options; To set the filtering on a log report
Reports Creating and generating a report FortiLog Administration Guide 05-16000-0082-20050115 61 6 Select the group or individual devices to use in the report. 7 Select Apply. Creating a device profile You can save the selections as a device profile. After creating a device profile, you can select t...
Page 62 - “Log policy” on page 42; Creating a filter profile; To create a report filter profile; Setting a report schedule; Figure 32: Report scheduling; To create a scheduled report
62 05-16000-0082-20050115 Fortinet Inc. Creating and generating a report Reports 4 Select the type of matching for the filter criteria:• Select Any to find any matches for the criteria specified.• Select All to find all criteria. All criteria must match to display in the results. 5 Select whether to...
Page 63 - Select a day from the following:; Creating a report schedule profile; To create a report schedule profile; Choosing the report destination and format; You can save the output options for use in other reports.; Daily; These Days; These Dates
Reports Creating and generating a report FortiLog Administration Guide 05-16000-0082-20050115 63 3 Select Schedule. 4 Select a day from the following: 5 Select a specified time of the day to run the report, up to three times per day. 6 Select Apply. Creating a report schedule profile You can save th...
Page 64 - To select the report destination and format; Creating a report destination and format profile; To create a pre-defined output selection; Reports on demand; To generate a report on demand; Email it
64 05-16000-0082-20050115 Fortinet Inc. Creating and generating a report Reports To select the report destination and format 1 Go to Reports > Config . 2 Select a report from the list. 3 Select Output. 4 Set the following options: 5 Select Apply. Creating a report destination and format profile Y...
Page 65 - Viewing reports; “Choosing the report destination and format” on page 63; To view a generated report; File Browse > Reports; Figure 34: Viewing reports; Report
Reports Viewing reports FortiLog Administration Guide 05-16000-0082-20050115 65 Viewing reports Use the FortiLog web-based manager to view a list of the generated reports. The generated reports are available in HTML, PDF, RTF and ASCII text formats, depending on the output configuration. For details...
Page 66 - Roll up report; Figure 35: Roll up report; Individual reports; Report title
66 05-16000-0082-20050115 Fortinet Inc. Viewing reports Reports Roll up report The roll up report contains all reports that you selected for the FortiLog unit to generate. Select the report name to view the report roll up in HTML format. Figure 35: Roll up report Select a report category to expand t...
Page 67 - Figure 36: VPN activity report in PDF; Vulnerability reports
Reports Vulnerability reports FortiLog Administration Guide 05-16000-0082-20050115 67 Figure 36: VPN activity report in PDF Vulnerability reports Vulnerability reports show any potential weaknesses to attacks that may exist for selected devices by displaying the available ports on a FortiGate device...
Page 68 - “Selecting report result parameters” on page 68; Selecting report result parameters; • the device IP addresses or alias names.; To define report result parameters
68 05-16000-0082-20050115 Fortinet Inc. Vulnerability reports Reports 3 Set the following: • “Selecting report result parameters” on page 68 • “Selecting plug-ins” on page 68 • “Selecting the scan targets for the report” on page 69 • “Choosing the report destination and format” on page 71 . 4 Select...
Page 69 - Figure 38: Vulnerability plugin options; To select the plug-ins; Creating a plug-in profile; To create a plug-in profile; Selecting the scan targets for the report
Reports Vulnerability reports FortiLog Administration Guide 05-16000-0082-20050115 69 Figure 38: Vulnerability plugin options To select the plug-ins 1 Go to Reports > Config > Vulnerabilities . 2 Select a report from the list. 3 Select Plug-ins. 4 Select the plug-ins to include in the report. ...
Page 70 - Figure 39: Selecting scan targets; To select the scan targets; Creating a scan target profile; To create a scan target profile
70 05-16000-0082-20050115 Fortinet Inc. Vulnerability reports Reports Figure 39: Selecting scan targets To select the scan targets 1 Go to Reports > Config > Vulnerability . 2 Select a report from the list. 3 Select Scan Targets. 4 Select devices from the Available IP Aliases list. 5 Select th...
Page 71 - Figure 40: Selecting report output; Email list
Reports Vulnerability reports FortiLog Administration Guide 05-16000-0082-20050115 71 4 Select Apply. Choosing the report destination and format Select destination and format for the vulnerability report. Configure the FortiLog unit to either save the reports to the FortiLog hard disk or email the r...
Page 72 - Viewing the vulnerability report; Figure 41: Viewing the list of vulnerability reports; To view the vulnerability report saved to the FortiLog hard disk; Action; Size
72 05-16000-0082-20050115 Fortinet Inc. Vulnerability reports Reports Viewing the vulnerability report The FortiLog unit saves the vulnerability report either to it hard disk or sends the report as an email attachment. Figure 41: Viewing the list of vulnerability reports To view the vulnerability re...
Page 73 - Using Logs
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 73 Using Logs The FortiLog unit collects log files from various sources and stores them on its hard disk. With the log viewer you can: • view log files collected from FortiGate, FortiManager, FortiMail and...
Page 74 - The Log view interface
74 05-16000-0082-20050115 Fortinet Inc. The Log view interface Using Logs The Log view interface The log viewer interface provides a means of viewing device log files. Figure 42: Viewing the logs Viewing logs The log viewer interface provides a display of log data that you can organize and format. D...
Page 75 - Figure 43: Viewing a device log; To view the device log files; FortiGate Log Message Reference; Finding log information; To perform a basic search of the log contents; Page
Using Logs Viewing logs FortiLog Administration Guide 05-16000-0082-20050115 75 Figure 43: Viewing a device log To view the device log files 1 Go to File Browse > Logs . 2 Select a device tab. 3 Expand the group name and device name to see the list of available logs. 4 In the Action column, selec...
Page 76 - To perform a standard search of the log contents
76 05-16000-0082-20050115 Fortinet Inc. Viewing logs Using Logs Figure 44: Basic log filter 5 Do the following to search the log using the Basic log filter: 6 Select Apply. To perform a standard search of the log contents 1 Go to File Browse > Logs . 2 Select a device and log file. 3 In the log v...
Page 77 - Importing log files; To import a log file
Using Logs Importing log files FortiLog Administration Guide 05-16000-0082-20050115 77 6 Select each row in the Filter column. 7 Each row of information provides criteria for the search: The row criteria available reflect the content within the selected log file. 8 Select Enable for each row you wan...
Page 78 - Log Search; To search the log files for specific information; File Browse > Log Search; Show
78 05-16000-0082-20050115 Fortinet Inc. Log Search Using Logs Log Search Use the Log Search, to perform a simple search of all log files on the FortiLog unit. The FortiLog unit maintains a search history for future use. If you need to clean out a long search history, select Clear History. To search ...
Page 79 - To run an event correlation:; File Browse > Event Correlation; Select an attack type from the list; Sort list
Using Logs Event correlation (Active mode) FortiLog Administration Guide 05-16000-0082-20050115 79 5 Select Apply. Event correlation (Active mode) Event correlation is a data mining feature that provides a way of reviewing attacks on multiple devices in one location. The FortiLog unit collates attac...
Page 81 - Using the FortiLog unit as a NAS; To view and manage files stored on the FortiLog hard drive; Connecting to the FortiLog file system
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 81 Using the FortiLog unit as a NAS Users can save, store and access information on the FortiLog hard disk as an alternate means of storing important files and work. To provide users with access to the For...
Page 82 - Providing access to the FortiLog hard disk; Selecting a file sharing protocol; To set the file sharing for the FortiLog unit; Network Sharing > Protocols; Select Enable for a file sharing protocol.; Adding and modifying user accounts; “Configure Administrator; To add a user account; Network Sharing > Users; Enter the following information for the user account:
82 05-16000-0082-20050115 Fortinet Inc. Providing access to the FortiLog hard disk Using the FortiLog unit as a NAS Providing access to the FortiLog hard disk To enable user access to the FortiLog hard disk to store and access files you need to add user and group accounts to the FortiLog unit. Along...
Page 83 - Adding and modifying group accounts; To add a user group; Network Sharing > Groups; Enter the following information for the group account:; Assigning access to folders; To add a new Windows share configuration; Network Shares > Access > Windows Shares; Group; GID
Using the FortiLog unit as a NAS Providing access to the FortiLog hard disk FortiLog Administration Guide 05-16000-0082-20050115 83 Adding and modifying group accounts Create user groups to assign directory access to many users at once rather than individually. To add a user group 1 Go to Network Sh...
Page 84 - Figure 49: Windows sharing configuration; To add a new NFS share configuration
84 05-16000-0082-20050115 Fortinet Inc. Providing access to the FortiLog hard disk Using the FortiLog unit as a NAS Figure 49: Windows sharing configuration 3 Select the Local Path button to select the folder for the users or groups to access. 4 Select OK. 5 Enter the Share Name to describe the shar...
Page 85 - Figure 50: NFS share configuration; Modifying the user or group folder access; To modify the FortiLog folder access; Network Sharing > Access
Using the FortiLog unit as a NAS Providing access to the FortiLog hard disk FortiLog Administration Guide 05-16000-0082-20050115 85 Figure 50: NFS share configuration 3 Select the Local Path button to select the folder for the users or groups to access. 4 Select OK. 5 Enter the IP address of the rem...
Page 86 - Setting folder and file properties; To set file and folder permissions
86 05-16000-0082-20050115 Fortinet Inc. Setting folder and file properties Using the FortiLog unit as a NAS Setting folder and file properties The FortiLog unit enables you to administer the folders and files on the FortiLog hard disk. Using the file browser you can: • rename and delete files and fo...
Page 87 - FortiLog CLI reference; CLI documentation conventions; restore config myfile.bak
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 87 FortiLog CLI reference This chapter explains how to connect to and use the FortiLog command line interface (CLI). You can use CLI commands to view all system information and to change all system configu...
Page 88 - Connecting to the CLI; Connecting to the FortiLog-800 console; To connect to the FortiLog-800 console; Bits per second
88 05-16000-0082-20050115 Fortinet Inc. Connecting to the CLI FortiLog CLI reference Connecting to the CLI The FortiLog-800 model has serial port and you can use the null modem cable to connect it to your management computer. The FortiLog-100 and 400 models do not support serial cable connections. Y...
Page 89 - Setting administrative access for SSH or Telnet; “Admin” on page 46; To use the CLI to configure SSH or Telnet access; set system interface port1 config allowaccess ssh
FortiLog CLI reference Connecting to the CLI FortiLog Administration Guide 05-16000-0082-20050115 89 10 Type the password for this administrator and press Enter.The following prompt appears: Welcome! You have connected to the FortiLog CLI, and you can enter CLI commands. Setting administrative acces...
Page 90 - Connecting to the FortiLog CLI using SSH; To connect to the CLI using SSH; Connecting to the FortiLog CLI using Telnet; To connect to the CLI using Telnet
90 05-16000-0082-20050115 Fortinet Inc. Connecting to the CLI FortiLog CLI reference 4 To confirm that you have configured SSH or Telnet access correctly, enter the following command to view the access settings for the interface: get system interface The CLI displays the settings, including the mana...
Page 91 - CLI commands; The FortiLog CLI commands include:; execute branch; Use
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 91 CLI commands The FortiLog CLI commands include: • execute branch • get branch • set branch • unset branch execute branch Use execute to run static commands, to reset the FortiLog unit to factory defaults, to ...
Page 92 - get branch
92 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference get branch Use get to display settings, logs, or system information. Table 5: get command architecture get alertemail configuration <return>setting <return> config <return> <keyword_str> <return>...
Page 94 - set branch; set alertemail
94 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference set branch Use set to configure settings, logs, or system information. set alertemail Use set alertemail to configure alert mails. Table 6: set alertemail command architecture set alertemail configuration auth {enable | disa...
Page 97 - set console
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 97 set console Use set console to set console configuration. Table 7: set console command architecture set console baudrate {9600 | 19200 | 38400 | 57600 | 115200} <return> mode batch <return> line &...
Page 98 - set log
98 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference set log Use set log to configure log settings Table 8: set log command architecture set log client <string> deviceid<string> secure {yes | no} psk <string> space <number> <return> filesz <int...
Page 99 - Table 8: set log command architecture
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 99 setlog devtype <string> report name <report name><Return> period from <YY-MM- DD-HH> to <YY-MM-DD- HH>today | yesterdaythis {year |quarter|month| week}last {year|quarter|m onth|w...
Page 100 - Commands
100 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference Commands Description set log client <client_string> deviceid <id_string> secure {yes | no} psk <psk_string> space <number> filesz <filesz_integer> fileage <fileage_integer> spacefull {ove...
Page 103 - set NAS
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 103 set NAS Use set NAS to configure the FortiLog NAS server settings when using the FortiLog unit in Passive mode. Table 9: set NAS command architecture set nas protocol nfsshare workgroup <workgroup> use...
Page 104 - set report; set system; set report command architecture
104 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference set report Use set report to configure the FortiLog report settings. set system Use set system to configure the FortiLog system settings. Table 10: set report command architecture set report resolve <services | aliases&g...
Page 105 - Table 11: set system command architecture
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 105 set system interface <intf_str> config denyaccess ping <return>https <return>ssh <return>snmp <return>http <return>telnet <return> wins <xxx.xxx.xxx.xxx> <r...
Page 109 - set system mainregpage hide
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 109 set system interface config stp_passthroughset system interface <intf_str> config mode static Set the interface mode to static. set system mainregpage hide Hide main registration message. set system se...
Page 110 - unset branch
110 05-16000-0082-20050115 Fortinet Inc. CLI commands FortiLog CLI reference unset branch Use unset to remove configuration of alert email, log, and system. set system time manual zone <No.> Set the system time zone by number. set system time manual dst {disable | enable} Enable or disable day...
Page 111 - unset report resolve
FortiLog CLI reference CLI commands FortiLog Administration Guide 05-16000-0082-20050115 111 unset nas user <user name> Remove a user name. unset nas group <group name> Remove a group name. unset nas share <share name> Remove a Windows-shared folder setting. unset nas nfs path <...
Page 113 - Appendix A: Log Report Types; Network Activity; Log report
FortiLog Administration Guide Version 1.6 FortiLog Administration Guide 05-16000-0082-20050115 113 Appendix A: Log Report Types Your FortiLog unit is can generate over 130 different types of log reports. Listed here are the log reports and a short description. Network Activity Network activity log r...
Page 114 - FTP Activity
114 05-16000-0082-20050115 Fortinet Inc. Appendix A: Log Report Types FTP Activity FTP reports record total FTP access activities including traffic direction, sites and connections. Web Traffic By Direction Total incoming and outgoing web traffic in kilobytes. Blocked Web Site Attempts By Date Attem...
Page 115 - Terminal Activity; Mail activity reports record Email traffic and connections.
Appendix A: Log Report Types FortiLog Administration Guide 05-16000-0082-20050115 115 Terminal Activity Terminal activity reports record total Terminal/CLI access activities. Mail Activity Mail activity reports record Email traffic and connections. Report Description Terminal Traffic By Date And Ser...
Page 116 - Intrusion Activity
116 05-16000-0082-20050115 Fortinet Inc. Appendix A: Log Report Types Intrusion Activity Intrusion activity reports record top network attacks and top attacks by a specific time. Antivirus Activity Antivirus activity reports record total antivirus attacks by time, attack event types, top senders, an...
Page 117 - Mail Filter Activity
Appendix A: Log Report Types FortiLog Administration Guide 05-16000-0082-20050115 117 Mail Filter Activity Mail filter activity reports record total and top mail filter activities by device, time, and top senders and receivers. Web Filter Events By Hour Of Day And Top Destinations Hourly web events ...
Page 118 - VPN Activity
118 05-16000-0082-20050115 Fortinet Inc. Appendix A: Log Report Types VPN Activity VPN activity reports record total VPN activities by a specific time and direction as well as top VPN activities. Content Activity Content activity reports record content activities by a specific time and direction as ...
Page 121 - Index
FortiLog Administration Guide 05-16000-0082-20050115 121 FortiLog Administration Guide Version 1.6 Index A access to files 82account levels 48active and passive mode 8administrator account 48 read & write access 48 read only access 48settings 46 administrator account netmask 108trusted host 49 A...