Logging and Monitoring Flashcards

1
Q

What are the three types of logs?

A

Traffic, events, Security logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do Traffic logs record?

A

traffic flow info, (http/https requests)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three types of traffic logs?

A

Forward, Local, Sniffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a forward log?

A

contains info about traffic FTG either accepted or rejected according to FW policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a local log?

A

contains info about the traffic directly to and from the FG management IP add. Includes connection to the GUI and FortiGaurd queries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are sniffer logs

A

contain information related to traffic seen by the one-arm sniffer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Event Logs?

A

Event logs record system and administrative events like adding or modifying a setting, or daemon activities or FortiGuard updates and GUI logins .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some examples of Event logs?

A

User, System, Router, VPN, Wifi

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are security logs?

A

record security events, such as virus attacks and intrusion attempts. They contain log entries based on the security profile type. (App Control, AV, DNS, File Filter, Web Filter, IP, SSL SSH)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the default number of days logs are stored on disk?

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the highest severity of a log?

A

0 = Emergency (system is unstable)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the lowest severity of a log

A

7 Debug (rarely used unless working with Fortisupport)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you are using one hard drive for WAN optimization can you use it for logging?

A

No, unless there is a second hard drive that is not being used for WAN optimization. If no second HD use syslog or FortiAnalyzer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How much space does FTG reserve for logging?

A

Approx 75%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are examples of Remote Logging Servers?

A

Syslog
FortiCloud
FortiAnalyzer
FortiSIEM
FortiManager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the differences between FortiManager and FortiAnalyzer from a logging perspective?

A

FortiManager limits logs volumes are limited to a fixed amount per day
Whereas FortiAnalyzer is meant to store and analyze logs so its limit is much higher.

16
Q

What process caches logs with FTG can’t reach FrotiAnalyzer?

A

miglogd (for long enough to reboot FortiAnalyzer)

17
Q

What port does FTG use for log transmission?

A

UDP 514

18
Q

What compression algorithm is used to compress logs

A

LZ4

19
Q

In a Firewall policy What does Logging allowed traffic setting do?

A

It needs to be turned on for any logging to occur

20
Q

In a Firewall policy What does only logging security events provide?

A

logs appear in the forward traffic log and security log.

21
Q

In a Firewall policy What does logging All sessions provide?

A

Every session generates a log and is logs appear in the security log events

22
Q

How do you anonymize logs of usernames?

A

config log setting
Set user-anonymize enable

23
Q

How do you view logs associated with a FW policy?

A

Right click on the policy and then click Show Matching Logs

24
Q

Your customer has configured FTG to send logs to FortiAnalyzer but the test connectivity button continues to show a failed connection. What’s wrong?

A

You need to register FTG to the FortiAnalyzer.

25
Q
A