记录日志

日志和报告

 

 

在远程电脑上记录日志

以下操作用于将 FortiGate 配置为将日志消息记录到一台远程电脑上。这台远程电 脑须配置为一个系统日志服务器。

1

进入 日志与报告 > 日志设置

 

2

选择 记录日志到远程主机 以发送日志到一个日志服务器上。

 

3

输入运行系统日志服务器软件的远程主机的 IP 地址

 

4

输入系统日志服务器的端口号。

 

5

选择您希望记录到日志的消息的紧急程度。

 

 

FortiGate 会将所有不低于您所选择的级别的消息记录进日志。例如,如果您希望记录

 

紧急、警报、危险和错误消息,选择错误。

 

6

单击配置策略。

 

 

·选择您希望 FortiGate 设备记录的日志的类型。

 

 

·对于每一种日志类型,选择选择您希望 FortiGate 设备进行的记录操作。

 

 

·单击确定。

 

 

关于日志类型和记录活动的详细信息请见 第 244 页 过滤日志消息

 

245 页 配置通讯日志

 

7

单击应用。

 

在 NetIQ WebTrends 服务器上记录日志

以下操作可以将 FortiGate 配置为在一台远程的 NetIQ 防火墙报告服务器上记录 日志 , 以供存储和分析之用。FortiGate 日志的格式服从 Web Trends Enhanced Log (WELF)格式规范,并与 Web Trends NetIQ 安全报告中心 2.0 和防火墙套件 4.1 容。可以从安全报告中心和防火墙套件的文档中获得更详细的信息。

注意:FortiGate 通讯日志消息包括发送和接收域,这些内容是在日志记录中可选的,是是绘 制 WebTrends 图表所须的内容。

以下操作将日志记录到一台 NetIQ Web Trends 服务器上:

1 进入 日志与报告 > 日志设置

2 选择 以 Web Trends Enhanced 日志式记录日志

3 输入 NetIP WebTrends 防火墙报告中心的 IP 地址

4 选择您希望记录到日志的消息的紧急程度。

FortiGate 会将所有不低于您所选择的级别的消息记录进日志。例如,如果您希望记录 紧急、警报、危险和错误消息,选择错误。

5

单击配置策略。

 

 

 

要对 FortiGate 过滤的日志类型和记录的事件进行配置,按

第 244 页 过滤

 

日志消息

第 245 页 配置通讯日志中的步骤操作。

6

单击应用。

 

 

将日志记录到 FortiGate 硬盘

如果您的系统中安装了硬盘,您可以将日志文件记录到硬盘

242

美国飞塔有限公司

Page 254
Image 254
Fortinet 500 manual 在远程电脑上记录日志, NetIQ WebTrends 服务器上记录日志, 将日志记录到 FortiGate 硬盘, 242

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.