This is an overview of the steps required to connect Fortinet firewalls to ContraForce.
Log forwarding can be configured in Fortinet/FortiAnalyzer through two different methods. Syslog forwarding can be setup via the Fortinet interface or the command line.
There are two different methods that can be used to connect a Fortinet firewall to ContraForce. The method to be used depends on the FortiOS version being used by the firewall. Older FortiOS versions (5 and below) require the command line to be used to set up log forwarding to ContraForce. Newer FortiOS versions (6 and above) allow for log forwarding to be setup within the user interface of FortiAnalyzer. Both methods are outlined below.
If you have any questions about this process please feel free to email support@contraforce.com!
Using FortiAnalyzer User Interface
Edit Log Forwarding
- From the home page, navigate to System Settings.
- In the left pane, navigate to Log Forwarding.
- Within the Log Forwarding page, select + Create New.
- Under Edit Log Forwarding, fill out the details to setup log forwarding to ContraForce.
- Name: ContraForce
- Status: Enabled
- Remote Server Type: Common Event Format (CEF)
- Server FQDN/IP: <VM Collector IP Address>
- Server Port: 514
- Reliable Connection: Enabled
- After the log forwarding details are completed, log forwarding filters and encryption can also be adjusted.
- Log Filters: Enabled
- Log messages that match: All
- Set Encryption Algorithm: High
- Once completed click "Ok."
- After completing the setup, let your ContraForce Customer Success representative know and they will confirm that the connection has been made to ContraForce.
Using the Command Line
- Navigate to the Fortinet Command Line
- config log syslogd setting
- set status enable
- set format cef
- set port 514
- set mode reliable
- set server <VM Collector IP Address>
- set enc-algorithm high
- end
- config log syslogd setting
Troubleshooting the Command Line
- The facility name by default should be local4.
- For very early versions of FortiOS the command set csv disable may also need to be ran.