Tuesday, December 27, 2016

Enable logging on Fortigate-VM for Azure

Fortinet Fortigate-VM for Azure marketplace image, comes without a disk for logging by default, so in order to have the logging ability, an additional disk needs to be added.

Note: This procedure requires a couple of reboots to the firewall, so best done prior to the Fortigate being in production environment.

Step 1: Add logical disk to the Fortigate VM via the Azure portal (Powershell can also be used):
Open the Fortigate VM blade -> Disks ->Attach new


Step 2: Reboot the Fortigate (without reboot the Fortigate will not detect the newly added disk) - reboot can be done from the Fortigate System dashboard:


Step 3: Once the Fortigate reloaded, go into the CLI console which is in the System dashboard and run the following command: execute formatlogdisk, a long reboot will occur (around 15 min).


Step 4: Once reboot is completed and the Fortigate is up and running again, go to the Log & Report -> Log Config -> Log settings and check the "Disk" and "Enable Local Reports" settings.


Step 5: Go to the Traffic Logs, generate traffic towards to Fortigate and check that the logs are shown.