FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nkorea
Staff
Staff
Article Id 268371
Description This article describes how to check ZTNA logs on FortiGate when only FortiAnalyzer logging is enabled and there is no disk or memory logging.
Scope

FortiOS 7.0.0+ and FortiAnalyzer 7.0.3+.

Solution

Verify that the following configuration has been implemented on FortiGate:

config firewall proxy- policy

    edit <policy number>

    ...

        set logtraffic all

    next

end

config firewall access-proxy

    edit <proxy>

        set log-blocked-traffic enable

    next

end

 

To enable logging to FortiAnalyzer.

 

Go to Security Fabric -> Logging & Analytics or Log & Report -> Log Settings.
Enable FortiAnalyzer.


Select an upload option: Realtime, Every Minute, or Every 5 Minutes (default). Select 'Apply'.

 

How to check the ZTNA log on FortiAnalyzer :

ZTNA traffic logs 7.0.3.

 

To view ZTNA logs:

 

  1. Go to Log View -> FortiGate -> Traffic.
  2. Filter by Log ID = 0005000024 or Sub Type = ztna.

 

nkorea_0-1691719075347.png

 

  1. Select a ZTNA log to view the log details pane. There are six new log details for ZTNA logs:
  • Access Proxy.
  • Client Device ID.
  • Client Device Owner.
  • Client Device Tags.
  • Gateway ID.
  • Virtual IP.

 

Make sure the FortiOS version is compatible with the FortiAnalyzer version.

Compatibility with FortiOS.

 

Note.

ZTNA traffic logs are not supported in FortiAnalyzer 6.4 or earlier.

 

Additional Resources on how to add FortiGate to FortiAnalyzer:
Adding a FortiGate using Security Fabric authorization.