Fortigate - Enable logs of failed connection attempts

Information

Enable or disable logging of failed connection attempts to the FortiGate unit that use TCP/IP ports other than the TCP/IP ports configured for management access (443 for https, 22 for ssh, 23 for telnet, and 80 for HTTP by default).

Solution

To enable logging, use the following command:

config log setting
set local-in-deny-unicast enable
set local-in-deny-broadcast enable
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: FortiGate

Control ID: 2d94569c12e13eea512ffd9a829f1ccda2e69d74bbb2d31c940d1880bc4c8528