8.2.1 Encrypt Log Transmission to FortiAnalyzer / FortiManager

Information

Enable encryption for logs that are sent to FortiAnalyzer or FortiManager.

Rationale:

Provides encryption for logs that are sent to FortiAnalyzer or FortiManager to prevent logs being collected and viewed as they traverse the network.

Solution

On GUI:

1. Go to Log & Report > Log Settings.
2. Configure 'Remote logging' to FortiAnalyzer/FortiManager.
3. Select 'Encrypt log transmission'

On CLI:

config log fortianalyzer setting
set enc-algorithm high
end

See Also

https://workbench.cisecurity.org/benchmarks/12961