Device Registration Adding devices You must add and register devices and VDOMs to FortiAnalyzer to enable the device or VDOM to send logs to FortiAnalyzer . In order for FortiAnalyzer to start collecting logs from a device, it must become a registered device on FortiAnalyzer . There are many ways you can register device using FortiAnalyzer . Serial Number Pre-shared Key Remote Logging Security Fabric Add HA Cluster
Device Registration Adding devices Before registration we need to configure SSL enc algorithm Fortigate Test Connectivity Failed SSL Error config system global set enc -algorithm low set ssl -low-encryption enable set oftp - ssl -protocol tlsv1.0 end FortiAnalyzer config log fortianalyzer setting set status enable set server 192.168.100.100 set reliable enable set ips -archive enable set certificate-verification enable set access- config enable set enc -algorithm low set ssl -min-proto-version default set conn-timeout set monitor- keepalive -period set monitor-failure-retry-period set upload-option realtime
Device Registration Adding devices To add a device, Go to Device Manager > Device & Groups. Add FortiGate Through Serial Number (Security Fabric):
Device Registration Adding devices In FortiGate Firewall Navigate to Security Fabric >Fabric Connectors> FortiAnalyzer Logging Add FortiGate Through Serial Number (Security Fabric):
Device Registration Adding devices Add FortiGate Through Serial Number (Security Fabric): In FortiGate Firewall Navigate to Security Fabric >Fabric Connectors> FortiAnalyzer Logging
Device Registration Adding devices In FortiGate Firewall Navigate to Security Fabric >Fabric Connectors> FortiAnalyzer Logging Add FortiGate Through Security Fabric:
Device Registration Adding devices In FortiGate Firewall Navigate to Security Fabric >Fabric Connectors> FortiAnalyzer Logging Add FortiGate Through Security Fabric:
Device Registration Adding devices Login to FortiAnalyzer in the root ADOM, go to Device Manager and click Unregistered Devices in the quick status bar. The content pane displays the unregistered devices. Add FortiGate Through Security Fabric:
Device Registration Adding devices In FortiGate Firewall Navigate to Log & Report >Log Setting> Remote Logging and Arching>Send logs to FortiAnalyzer / FortiManager type the IP Address of FortiAnalyzer . Click Apply. Add FortiGate Through Log Setting:
Device Registration Adding devices Add FortiGate Through Log Setting: Login to FortiAnalyzer in the root ADOM, go to Device Manager and click Unregistered Devices in the quick status bar. The content pane displays the unregistered devices.
Device Registration Adding devices Go to Device Manager > Device & Groups. Click Add Device. The Add Device wizard displays. Enter the name of the Device type the Pre-Shared Key and Device Model Click Next Add FortiGate Through Pre-Shared Key:
Device Registration Adding devices In the FortiGate CLI, configure the pre-shared key to match the one configured on the FortiAnalyzer . Add FortiGate Through Pre-Shared Key: config log fortianalyzer setting ( setting) # set status enable ( setting) # set server "192.168.114.210" ( setting) # set serial "FAZ-VMTM22007258" ( setting) # set preshared -key "123456" ( setting) # set source- ip "192.168.114.230" ( setting) # set upload-option realtime ( setting) # end
Device Registration Adding devices In FortiGate Firewall Navigate to Log & Report >Log Setting> Remote Logging and Arching>Send logs to FortiAnalyzer / FortiManager type the IP Address of FortiAnalyzer . Click Apply. At this time, the connection status is unauthorized. Add FortiGate Through Pre-Shared Key:
THANKS! KEEP IN TOUCH www.linkedin.com/in/saeedabdelhalimhamada [email protected] www.youtube.com/c/mindsets1 Saeed Abd Elhalim Hamada