Fortigate - Enable logs of failed connection attempts

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enable or disable logging of failed connection attempts to the FortiGate unit that use TCP/IP ports other than the TCP/IP ports configured for management access (443 for https, 22 for ssh, 23 for telnet, and 80 for HTTP by default).

Solution

To enable logging, use the following command:

config log setting
set local-in-deny-unicast enable
set local-in-deny-broadcast enable
end

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: FortiGate

Control ID: 4ffbbf3fc8096b58f6030e30b291dfd5a9d28d2baf36bb15b91d99746eab359f