This article explains how to enable the Log Archiving feature on the FortiGate in FortiOS 4.0 MR2 and provides a list of the hardware devices that support this feature.
FortiOS 4.0 MR2 and above
In FortiOS 4.0 MR2, FortiGate devices with local hard drives support:
1. Content archive.
2. DLP archive.
3. IPS Packet Log (PCAP).
4. Quarantine.
The Quarantine feature has been available since the FortiOS 4.0 GA release.The FortiGate hardware platforms that support these features are shown in the following table.
Internal HDD (new) FG-51B, FG-60C, FWF-81CM AMC FG-310B, FG-620B, FG-3016B, FG-3600A, FG-3040B, FG-3140B, FG-3810A, FG-3961B, FG-5001A SDD FG-82C, FG-111C, FG-200B, FG-311B, FG-1240B To configure archiving to the local hard disk use the CLI command:
config log disk filter
set dlp-archive {enable | disable}
endTo configure the web based manager go to Log&Report>Log Config>Log Setting.
Configure DLP archive and enable DLP in the firewall policy so that the archives are seen on the disk.
To view the archives go to Log&Report>Archive Access>E-mail.
.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.