FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 198118
Article
DescriptionUsing a FortiLog unit with a FortiGate unit and an MSSP reporting platform.
Components
  • All FortiGate units
  • FortiLog with firmware version 3.0
Steps or Commands

Depending on how the MSSP operates, there can be several different options for logging and generating reports using a FortiLog unit.

MSSP using VDOM

Typically, one VDOM is partitioned per customer. The FortiGate unit sends all logs to the FortiLog unit. Included in the log message is the field "vdom=". When configuring the report profile on the FortiLog unit, in the Log Filter section, select Custom for the filter and enter the IP address for the VDOM. By adding this parameter, the FortiLog unit only uses logs for the indicated VDOM in the report.

MSSP uses separate FortiGate unit per customer

In this scenario, a separate FortiGate unit is partitioned per customer. When configuring the report profile, select the FortiGate unit belonging to that customer. Only that log information is included in the report.

MSSP uses IP address/IP range/interface to identify customer

In this scenario, a similar filtering option to the first example can be used. While the report configuration currently does not support an IP range, you can enter a source and destination IP address, source interface, and so on. The FortiLog unit can send the report results automatically to customers by email once the FortiLog unit has generated. You can also configure reports to run on a regular schedule, for example, to generate a monthly report. For more information on FortiLog report generation, see the FortiLog Administration Guide.