Skip to content
CBT Nuggets
DemoBook a Demo

Understand FortiAnalyzer Key Concepts

The skill focuses on FortiAnalyzer, a centralized analytics and reporting platform used with Fortinet security devices like FortiGate firewalls. It highlights the integration of FortiAnalyzer for improved threat detection, compliance, and network visibility through centralized logging and event management. The content covers the configuration of FortiAnalyzer, its operating modes, and the benefits of using Fortinet's Security Fabric to reduce duplicate logs. Additionally, it explains the use of SQL databases for organizing log data and the importance of administrative domains for managing access and permissions.

Full skill from Fortinet FortiAnalyzer. Preview the IT training 23,000+ organizations trust.

52m

Skill 1 of 6 in Fortinet FortiAnalyzer

Intro to Understand FortiAnalyzer Key Concepts

Keith introduces this set of videos regarding the FortiAnalyzer from Fortinet.

FortiAnalyzer Key Concepts Overview

Keith presents an overview of the benefits and functions of FortiAnalyzer, a centralized analytics and reporting platform used in conjunction with Fortinet security devices, such as FortiGate firewalls. This enables organizations to collect, analyze, and visualize security events, thereby improving threat detection, compliance, and network visibility.

Knowledge Check

What is one of the main benefits of using FortiAnalyzer in conjunction with Fortinet security devices?

Initial Access to FortiAnalyzer

Keith explains the initial configuration needed and methods to access a FortiAnalyzer.

Knowledge Check

What is the initial step to connect a FortiAnalyzer to the public Internet?

Centralized Logging with FortiAnalyzer

Keith demonstrates some of the benefits of FortiAnalyzer, including centralized logging.

Knowledge Check

What is the first step to configure a FortiGate firewall to send logs to FortiAnalyzer?

Fortinet Security Fabric and FortiAnalyzer

The Fortinet Security Fabric provides several key benefits when sending logs from multiple FortiGate firewalls to a FortiAnalyzer, especially in environments where you want unified visibility, control, and automated response across your network. Devices in the fabric can share log forwarding and event handling policies, reducing duplication of config and policy. In this video, Keith demonstrates how to configure the three firewalls at the HQ location into a single security fabric.

Knowledge Check

What is a benefit of configuring multiple FortiGate firewalls into a single security fabric when sending logs to a FortiAnalyzer?

Working with Logs and FortiView

Keith demonstrates examples of using the logging sent to FortiAnalyzer as a way to see and sort through the log messages from multiple devices on FortiAnalyzer.

Knowledge Check

Which of the following are functionalities or features of FortiAnalyzer as discussed or demonstrated in the video? (Choose 3)

FortiAnalyzer Scenario

In this video, Keith presents a scenario for you to consider regarding a company that is considering the addition of a FortiAnalyzer.

Knowledge Check

How does the FortiAnalyzer store log and event data?

View Transcript

Intro to Understand FortiAnalyzer Key Concepts

0:00Hello and welcome. My name is Keith Barker and in this set of videos we're

0:04going to take a look

0:04at the basic concepts and fundamentals. We've got this wonderful tool called

0:08"40 Analyzer from Fordnet".

FortiAnalyzer Key Concepts Overview

0:00So as we begin our discussion of the beautiful tool called 40 Analyzer, let's

0:04also take a minute

0:05and let me review this topology with you which we'll be using throughout this

0:08course. So here I've

0:10got four firewalls or 440 gates. I've got one called HQ firewall one right here

0:14. I've got one

0:15called HQ firewall two right here one called HQ firewall three right there. And

0:19over here I have

0:20a branch firewall and it also has an HA pair which I think at the moment maybe

0:24offline but in any case

0:25I've got a firewall here at the branch office as well. Now for instructions on

0:29how to configure the

0:2940 gates themselves and configure them and their policies. We have separate

0:33content here at CBT

0:34nuggets on that topic as well. And as we continue together in this 40 analyzer

0:39course we're going

0:39to be focusing on the integration of the use of this tool right here called 40

0:43Analyzer. So let's

0:44begin with the purpose. Why would we even want to have this device called 40

0:48Analyzer? Well one of

0:49the main benefits of having a 40 Analyzer it can act as a central clearing

0:53house for all of our

0:54log information coming from not just 40 gate firewalls but also lots of

0:58different for net devices. So

1:00we're all right out centralized logs and that way you and I we can log in to 40

1:06Analyzer and they'll

1:07have those logs from all of our devices. So we have a single pane of glass

1:10where we can look at and

1:12analyze and do investigations regarding all the log messages coming from our

1:16for net devices. Now

1:17in order to get those logs from these devices over to the 40 Analyzer we're

1:21going to do a couple

1:21things. Number one we're going to register our devices for example firewall two

1:25firewall three

1:26firewall one the branch firewall will register all those with the 40 Analyzer

1:30and that way not

1:31just any device can go ahead and send logs they'll have to be registered where

1:34the 40 Analyzer is

1:35accepting those log messages and then at the 40 Analyzer it can buffer and

1:39organize and keep all

1:40that information regarding the logs and then what we can do so this is us right

1:44here. Us as

1:44administrators can then go ahead and log in to 40 Analyzer to do the

1:47investigation we can view

1:49and search the logs we can drill down into the details and also create reports

1:53instead of automated

1:54reports regarding what's happening in our environment. And one of the major

1:57benefits of having all that

1:58data right here is that we can then correlate different events that are

2:01happening across different

2:02devices to help identify what's really happening on the network. For example do

2:06we have a virus or

2:07some malware or some other activity where it's being seen by multiple devices

2:11we can then

2:12collect all that and analyze it right here at the 40 Analyzer. So the types of

2:15information logs

2:16that we're going to have here are going to include things such as security

2:19events things like malware

2:21showing up or denial of service attacks or some other intrusion prevention

2:24related activities

2:25as well as system events for example configurations being changed on our

2:29devices or who logged on who

2:31logged off as well as traffic logs all of that can be contained here at the 40

2:35Analyzer. Now behind

2:36the scenes the 40 Analyzer is going to use a structured query language database

2:40and that's spelled

2:41SQL and you can either spell it out like that SQL or it can say SQL and SQL

2:46stands for structured

2:47query language. So behind the scenes 40 Analyzer is taking all that data coming

2:51in putting into

2:52this database the SQL database and then when you and I connect to and log into

2:55the 40 Analyzer it

2:56can present that information in nice easy format for us including generating

2:59reports but again

3:00behind the scenes it was using SQL and that type of database to keep track and

3:04organize everything.

3:05And there's many different types of SQL databases and on the 40 Analyzer the

3:09one they use is right

3:10here. So a person doesn't have to be an expert at SQL however for some of the

3:14advanced reporting

3:15capabilities if you're familiar with SQL and how it works it would be easier to

3:19generate some of

3:19those reports. So make the notice a little bit and let's talk about a few other

3:23benefits and

3:24functions of 40 Analyzer. So let me go ahead and clean this up a little bit and

3:27let's chat about

3:28some of the other fundamentals regarding 40 Analyzer. There's two different

3:31operating modes that a

3:3240 Analyzer can operate in and the default one is Analyzer and when the 40

3:37Analyzer is in Analyzer

3:39mode it's going to act just as we discussed where we have different devices

3:42that have registered

3:43with that 40 Analyzer. All that log and event information is being sent over

3:47and then you and

3:48I log into the 40 Analyzer to see all the details. So with Analyzer mode

3:51devices are sending their

3:52logs directly to the 40 Analyzer. Now the other mode is called collector mode

3:56and think of a 40

3:57Analyzer in collector mode is like being a middleman. So let's imagine we have

4:01a 40 gate firewall here

4:02that's forwarding its logs over to a collector really it's a 40 Analyzer that's

4:07in collector mode

4:08so I'll put FAZ here in collector mode and then the collector can then forward

4:12those over to another

4:1340 Analyzer that's operating in Analyzer mode and it's really simple to flip

4:18the switch to tell the

4:1940 Analyzer to be in collector mode or Analyzer mode and in small environments

4:23we're going to just

4:24skip the middleman and have our 40 gates and other 4-net devices send their

4:27information directly to

4:28the 40 Analyzer but in a bigger environment with wide area networking as

4:32possible we may want to

4:33use multiple collectors who then forward it to our 40 Analyzers and if so that

4:37would be the hierarchy

4:38right here. 40 gates and other 4-net devices sending them to the collector and

4:42then the collectors

4:43forwarding them to the 40 Analyzer. Now one thing to be aware of regarding a 40

4:47Analyzer in collector

4:48mode is that we cannot at that device generate your ports and dig into the

4:53details we can only do

4:54that in a 40 Analyzer that set up in Analyzer mode. Now another aspect that we

4:58want to be aware of

4:59is a really cool feature inside of 4-net with 40 gates called a security fabric

5:03. So let's imagine

5:04that this firewall firewall 1 and firewall 2 and firewall 3 are all part of the

5:10same security fabric.

5:11Now in the security fabric let's also imagine that all three are sending their

5:15login information

5:16over to the 40 Analyzer. Now if this Windows computer right here or this PC

5:20right here has

5:21some event that happens and that traffic is for example going out to the public

5:25internet that

5:26traffic would go through firewall 2 and through firewall 1 and one would think

5:31well we're going

5:31to have duplicate logs but fortunately on the 40 Analyzer if we have this 40

5:35gate security fabric

5:36here the 40 Analyzer realizes those are all part of the same security fabric

5:40and it's going to help

5:41reduce the duplicates regarding the logging. Also not every firewall has the

5:46same rules some

5:47firewalls may be focused on denial of service attacks other firewalls may be

5:51focused on authentication

5:52and network address translation. So the cool thing is because the 40 Analyzer

5:56is also from

5:564-net it understands the security fabric it's going to help reduce duplicate

6:01log messages

6:02if it's showing the same information and that way of the best of both worlds we

6:05can get the logs

6:06and security events regarding traffic that's going through and we don't have to

6:09worry about a

6:09bunch of duplicate logs regarding the exact same traffic flow or the exact same

6:13events.

6:14And while we're talking about fabric let's also chat about another concept

6:17regarding fabric but

6:18this time regarding 40 Analyzer and a 40 Analyzer fabric. So let me clean up

6:24some of this right here

6:25and let's talk about 40 Analyzer fabric. So let's imagine we have several 40

6:29Analyzers in our

6:30Enterprise we'll call this FAS 1 and what this is FAS 2 and over here FAS 3 and

6:36let's imagine these

6:37are all in Analyzer mode and just for grins let's also throw in FAS E4 which is

6:42going to be in

6:43collector mode. So we can have some devices that are affording their logs and

6:47event information to FAS 4

6:49as a collector who can then forward it to for example FAS 2 we're going to have

6:52other devices

6:53that are forwarding directly to FAS 3 and then FAS 2 and FAS 3 even though they

6:57're an analyzer

6:58mode can still forward their logs over to FAS 1. If we've set up the 40 Analy

7:03zer fabric and here's

7:04how it would work we would configure FAS 1 here as a supervisor as part of the

7:08fabric which is kind

7:09of equivalent to a root of the security fabric with 40 gates so in the 40 Analy

7:14zer fabric we'd

7:15have one the second as a supervisor and then these two could behave as members

7:19which allows them to

7:20forward logs information to the supervisor and then 40 Analyzer 4 which is not

7:25an analyzer mode

7:26because in collector mode it can't actually become part of the fabric it's just

7:30forwarding

7:30information to the 40 Analyzer it was told to. So the 40 Analyzer fabric let me

7:34go ahead and put

7:35this in blue would be this part right here with the members forwarding to the

7:40supervisor and then a

7:4140 Analyzer operating in collector mode would not become part of that fabric

7:45although it'd be

7:46forwarding to one of the members in that fabric. So as far as what we've

7:49covered so far in this

7:50overview we have the 40 gate security fabric which the 40 Analyzer can sort out

7:55and reduce

7:56duplicate events we also have the 40 Analyzer fabric which if we have multiple

8:0040 Analyzers

8:01one would be supervisor and the other would be members in Analyzer mode so that

8:04's an example of

8:05the 40 Analyzer fabric. Another concept I'd like to share with you in this

8:08overview is the concept of

8:10administrative domains or ADOMS for short. Now in the 40 gates we have

8:15something called V-DOMS

8:16where we logically segment a firewall into multiple logical sub-firewalls if

8:21you will and with 40

8:23Analyzer we can set up 8 ADOMS administrative domains for the benefit of being

8:27able to give

8:28permissions to administrators to analyze and work with parts of the topology.

8:32So by setting up

8:33administrative domains we can have 140 Analyzer for example that's getting logs

8:37from all four of

8:38our firewalls but perhaps we have one administrative domain for these three

8:42firewalls at the head

8:43corridor location and we have a separate administrative domain regarding the

8:47branch firewall and that

8:48way different administrators could have different access and permissions as

8:51they interact with the

8:5240 Analyzer depending on which administrative domain they've been given access

8:56and privileges

8:57to. And one other aspect that's really important when bringing up a new 40

9:01Analyzer is understanding

9:03our options for connecting to it and the two major options are connecting via

9:07the command line

9:08interface or we could use the GUI and we think of the GUI like a browser using

9:12a browser to

9:13connect to the 40 Analyzer to do our work and at the 40 Analyzer we can specify

9:17via permissions

9:18exactly what is allowed regarding connecting to it. So for the CLI we can able

9:22things like SSH

9:23and for the GUI we can have HTTPS we also could allow HTTP although that's

9:28insecure because it's

9:29not encrypted and then for the CLI once we're at the GUI we also have an option

9:33from the GUI from

9:34the browser interface when we're working with the 40 Analyzer to go ahead and

9:36click a button to get

9:37a CLI to the 40 Analyzer should we need to issue command line interface

9:41commands. So as we go through

9:43this content together I'll give you examples of working with these options

9:47including options

9:48regarding how to connect to the 40 Analyzer.

Initial Access to FortiAnalyzer

0:00In this video, I'd like to do a couple just quick tests regarding the network

0:03topology and also

0:04walk you through access to the 40 Analyzer. Now, the 40 Analyzer itself can be

0:09deployed as an

0:10appliance or it can be deployed as a virtual machine. There's platforms as far

0:14as virtual

0:15machines are concerned for Microsoft and for VMware and others. And in my

0:20environment, in my lab

0:21environment, I've deployed this on an ESXi host. That's a host running VMware's

0:26virtualization software.

0:28And for its management interface, I put it on my management network, which is

0:31192.168.1.0 with

0:35the slash 24. And it's IP address I gave it is .81. However, the challenge is

0:39that when you get a

0:40brand new 40 Analyzer, it's very likely not going to have the IP address that

0:45you want it to have.

0:46Also, that 40 Analyzer is probably not going to have the correct default

0:50gateway information.

0:51It may have the default DNS servers to use, which would be fine. But to get it

0:55up and running

0:56and connected up to the cloud to Fortinet so it can get licensed and validated,

1:00it's going to need to

1:01have a workable IP address with a gateway in the case of a private RFC 19

1:05address like this.

1:07It's going to need to have NAT as well, network address translation. And also,

1:11as I mentioned,

1:11it needs DNS. It can do name resolution to connect to home to connect up to the

1:16Fortinet servers.

1:17So what I would like to do is I would like to go ahead and show you this 40

1:21Analyzer that I have

1:22where it's currently being deployed in VMware. And then I'd like to also walk

1:26you through

1:26how we can see from the command line interface what the IP address is and also

1:31what the gateway is

1:32and the DNS information is. And that way, we can change it should we need to

1:36and we will,

1:36especially the default gateway so that we can have this 40 Analyzer connect out

1:41to the public

1:41Internet. So I'm going to use a terminal emulator called secure CRT. And I have

1:45an entry right here

1:47that's going to use SSH to connect to 192.168.1.81, which is the 40 Analyzer I

1:53have set up in my lab

1:54environment. I also through scripting told it to submit the username and

1:58password, which is admin

2:00with the password I'm using on this device. So the first thing I did is I

2:04configured port one

2:06as part of the interfaces and gave it the IP address I needed in my environment

2:09. So to do that,

2:10I did a config system interface. I then typed in edit port one. That's the

2:14first logical network

2:16interface on this virtual machine, the 40 Analyzer. And then here I'm just

2:19going to show you the

2:21current configuration that I have, which is for port one, the IP address is set

2:25to this address

2:26ending in dot 81 on my management network. I've also set allow access for ping,

2:31HTTPS SSH and HTTP.

2:33But you know what, I really don't need HTTP. So let me go ahead and take that

2:37off. I'll do an

2:38edit port one. Oh, I'm already in port one. So I'm going to go ahead and do a

2:42set allow access for

2:43ping HTTPS and SSH only. So I'll copy and paste that press enter. And then we

2:48'll do a show just

2:48to make sure that took because I don't need HTTP. I'm going to use just HTTPS

2:52for the GUI. So the

2:53default IP address on most fortunate devices is going to be 192, once state 1.

2:5899. And so in my

3:00topology, I wanted to be 81. And that's why I said it here. So let me go ahead

3:03and clear the screen.

3:04The next thing I chose to do, which I didn't have to because the defaults were

3:07going to be fine is

3:08I specified DNS using 8888. And that's Google. And the secondary is from Cloud

3:14flare. But you could

3:15just take the defaults and that would work. And then finally, I also set up my

3:20routing. So in my

3:21environment, my default gateway for my management network going out to the

3:24public internet is 192

3:25once state 1.1. So I set up the routing to tell it specifically the correct

3:31default gateway to use.

3:33Because if you don't have a default route, the 40 analyzer can't get off the

3:36local network and

3:37won't be able to reach out to the cloud for getting the license validated. Also

3:41, my experience has

3:42been with the 40 analyzer. If you haven't deployed a 40 analyzer yet and you

3:45want to download it,

3:47there's an option for a trial license. I think it's good for some period of

3:51days where you can work

3:52with it and play with it just to get comfortable with it as well. That would

3:55require setting up

3:56an account up at Fortinet and then downloading the software and then deploying

4:00it and then choosing

4:01the option for using a trial license. So for my 40 analyzer, if I use the

4:04command GetSystemStatus,

4:06I added some licenses to it so I could demonstrate the things I needed to. And

4:10currently I'm using

4:11version 474, which is a mature version. There was also an option of using a

4:17feature version,

4:18but sometimes those have bugs. It's also specifying here the maximum number of

4:22administrative domains

4:22we can set up as five and it also shows here that the current license is valid.

4:27So if we confirm the

4:28IP address once again, it's 192.168.1.81. Let's go ahead and open up a browser

4:33for my management

4:34computer and connect to it via GUI. So that's what I've done right here. I'm in

4:37fullscreen mode,

4:38so I connected to https colon slash 192.168.1.81. And I'm going to specify the

4:44using a password I

4:45have for this device, which is admin and then my lab password and click on

4:50login. I also took

4:51a moment to chose this cute cat background for it and that's optional as well.

4:55You don't have to

4:56you can take the default. It works just as well. So I'll click on login and

4:59here we are directly

5:00connected to the 40 analyzer interface. So just to confirm the two options for

5:06connecting initially

5:07to the 40 analyzer would be through the CLI, which may be through a console

5:11cable. If you're going to

5:12a physical device or through VMware or Hyper-V, it could be a console provided

5:17by that virtualized

5:18environment. And then once you have the IP address all set up the way you need

5:21to and the default

5:22gateway setup, we could then go ahead and connect to be a browser to connect to

5:26the device. Also,

5:27from the GUI here we could verify our settings. So if we get on the system

5:30settings and go down

5:31to network, this would confirm for us our IP address on port one that I'm

5:35currently using and also our

5:37DNS information is shown right here as well. If we scroll down here's our

5:40default route as well.

5:42But once again to get the initial connectivity to the internet and to connect

5:45to this device,

5:46we'd want to go to the command line interface and specify the IP address as

5:50well as the default

5:51gateway so that device can be registered.

Centralized Logging with FortiAnalyzer

0:00So now that we have the 40 Analyzer verified, it's reachable by our management

0:04computer.

0:04Let me walk you through how we can add individual devices like 40 gate firew

0:08alls to send their

0:09logging information and event information over to the 40 Analyzer. So at the

0:13moment,

0:13I currently have firewall one and also the branch firewall here, both setting

0:18their log

0:18information over to the 40 Analyzer. But what isn't happening is I don't have

0:22firewall two or

0:23firewall three yet setting their log information over. So it's really simple to

0:28both tell these

0:28firewalls to send the logs. It's also very simple to sell the 40 Analyzer to

0:32welcome those incoming

0:33logs. So let's demonstrate that right now. So this is the 40 Analyzer and

0:38currently to see who is

0:39sending logs to this device, we go to device manager. And with device manager

0:44selected,

0:44it's showing us that we have hg firewall one, and also this device over at dot

0:5071 on my management

0:51network, which is the branch firewall that's saying it over as well. And

0:54because this firewall

0:55right here is part of a h a cluster. That's why it's showing up with this name

0:59right here cluster

1:00one fgd 60 f also I thought it'd be interesting to go ahead and have firewall

1:04one here with a feature

1:06release seven six and the firewall over at the branch office is currently 748,

1:12which is the as of

1:13this recording, one of the more mature versions available for the 40 us. So

1:17again, what's not here

1:18is firewall two and firewall three. And just to confirm where they are on the

1:21topology firewall

1:22two is right here. And firewall three is right here. And my 192 168 one

1:26management network is

1:28consistent across the rest. So firewall two ends in dot 52 for its management

1:32interface,

1:32firewall three ends in dot 53. So with that in mind, let's go over to firewall

1:36two and firewall three

1:37and tell them to start sending their logs over to the 40 analyzer. So here is

1:41firewall two just at

1:43the top left there shows us the actual name at hq firewall two. And now to tell

1:47this firewall

1:48firewall to to start sending log and event messages over to the 40 analyzer, we

1:52're going to go

1:52down to security fabric, and then we're going to click on external connectors.

1:55So here on firewall

1:56two, we're going to go down to security fabric and click on fabric connectors.

2:00And here for logging

2:01and analytics, currently, we're not logging to a 40 analyzer. So we'll click

2:05here, then click on

2:06edit, and then specify for 40 analyzer, we want to enable logging, and then we

2:11'll specify where

2:11we're going to log to, and we'll put in the IP address that's reachable on our

2:14measurement network,

2:15which is 192 dot 168 dot 1 dot 81. And then let's go ahead and say real time

2:21uploads. And that way,

2:22when something happens at this 40 gate regarding logs and events, it can

2:25immediately send them

2:26over. And then we'll click on, okay, 40 analyzer needs to approve and authorize

2:30the inbound

2:32messages from firewall two. So that's an additional step that needs to happen

2:35as well. So we'll take

2:36care of that as well. So I'll click on accept here. And let's go on to firewall

2:39three and tell

2:40it also to start sending log information over to the 40 analyzer. So here we

2:45are at firewall three. I

2:46did slightly change the color coding here. So that's easy to recognize it's a

2:50different firewall.

2:51So we're on firewall three. Once again, we go down to security fabric, and then

2:55we go to fabric

2:56connectors. And then here in the section called logging and analytics, we'll go

2:59ahead and click on

3:00that, and then click on edit, and then specify one to enable 40 analyzer

3:04logging, and then specify

3:06the IP address of our 40 analyzer, which is 192.168.1.81. And let's also do

3:12real time there as well,

3:13and click on okay. And then once again, before this allowed to actually send

3:16the logs, we need to

3:17authorize that over at the 40 analyzer. So click on accept there, and then we

3:22'll go to the 40 analyzer

3:23and say, Hey, you know, these two firewalls firewall two and firewall three,

3:26they both would like to

3:27log to is that okay? And once the 40 analyzer says yes, then firewall two and

3:31firewall three can

3:32start forwarding their logs. So back to the 40 analyzer, we go and here under

3:37device manager,

3:38you'll notice we have two firewalls that are authorized logging devices. And

3:42then we have couple

3:43here that are unauthorized. So if we click on that, it's going to show us those

3:46two firewalls.

3:47That's firewall two and firewall three. So we just click on both of them to

3:50select them,

3:51and then click on authorize. And it's asking us to confirm also right here, if

3:54we had set up

3:55multiple administrative domains, we could actually associate these firewalls

3:59with a specific

4:00administrative domain. So I'm going to put these in the root domain effectively

4:03, we're not using

4:04multiple adams yet, and we'll click on okay, so it's doing the device

4:07authorization, and that may

4:08take a moment or two. So we'll click on close, it's now starting to up and two

4:12down. But here in a

4:13moment firewall two and firewall three should show up as well. So we'll give

4:16that a moment to go

4:17ahead and settle. Meanwhile, let's go take a look at firewall two and firewall

4:20three. So here's

4:22firewall two, it still says unauthorized. So let's go ahead and refresh this

4:26page by just bouncing

4:27off and coming back to it. And the 40 analyzer hasn't finished its work yet. So

4:30let's also verify

4:31on firewall three. And there we go firewall three doesn't show a problem, which

4:34is 40 analyzer

4:35connected fantastic. Let's go back to firewall two. So back at firewall two,

4:39sure enough, we are

4:40now showing connected there. And if we go back to the 40 analyzer and do a

4:43refresh there, it shows

4:45three up one down. But I imagine here for way just a moment or two, it should

4:49show us that we have

4:50four out of four up. So let me go ahead and click on device manager again. And

4:54sure enough, we have

4:55four out of four up and reporting. So all the logs now from these four 48 firew

5:01alls are being sent

5:02over to 40 analyzer. So as the test here's what I propose we do, let's go to PC

5:07two. And let's go

5:08ahead and forward some traffic out to the internet. And that information

5:12regarding PC two should be

5:13sent over to 40 analyzer. Also be aware that at the moment firewall two

5:18firewall three and firewall

5:19one are not part of the same security fabric. So until we have that set up, we

5:23may have some

5:24duplicate logs as well. So let's go to PC two and send some traffic out to the

5:28internet. So here is

5:30PC two, let me go ahead and open up a browser. And on one of the two firewalls,

5:35and it's going to be

5:36either firewall two or firewall one, they're requiring authentication. So open

5:40the network login page,

5:41then we'll log on is ad dash user dash two, I'll put in the password for that

5:46user, and then we'll

5:46click on continue. Fantastic. And let's go to for net.com. So I'll close that

5:51browser. So that

5:52traffic should be logged here on firewall two and also here at firewall one, as

5:57that client's traffic

5:58is going out to the internet. And because firewall two and firewall one are

6:01both reporting to 40 analyzer,

6:03we should be able to see both of those logs right here at the 40 analyzer

6:07regarding PC two's traffic.

6:09In fact, let's generate some traffic that'll be really easy to identify. So let

6:12's go to YouTube,

6:13and that way it'll be easier to pick it out of the crowd. All right, so we're

6:16going to YouTube,

6:17fantastic. I'll close that. I'll minimize that browser. And let's go back to

6:21the 40 analyzer

6:22and take a look at the logs. So back at 40 analyzer, we're going to talk a lot

6:26about the

6:26different options here to look at the details and logs. But if we go to log

6:31view, and then we go to

6:3240 gate, we can look at the individual 40 gate firewalls at their logs. And

6:36what's really happening

6:37is we're not reaching out and looking at the logs at those 40 gates, those 40

6:40gates have already

6:41sent that log information over to the 40 analyzer. So currently I have traffic

6:46selected,

6:46looking at the traffic logs. So here in the traffic logs, if we want to sort

6:50out based on

6:5040 firewall, I can say instead of looking at all devices, let's take a look at

6:54firewall two,

6:55and we'll click on okay. And this is just going to show us the logs that were

6:58sent over from

6:59firewall two, which is our Linux client right here. So if we click on that, it

7:03's 10, 20,

7:030, 1, 0, 2, let me just confirm that's the IP address on our Linux device,

7:07which is PC two. So

7:08we'll bring up a command prompt here, and do an IF config. And sure enough, 10

7:13dot 20 dot 0 dot 1,

7:140, 2. Then if we go back up here and say, you know, instead of just firewall

7:17two, let's go ahead and

7:18change that just to firewall one and click on okay. Once again, we should be

7:23able to

7:23see information from firewall one's perspective about the traffic. So if we

7:27scroll down and go to

7:29page two, there we go. There's 80 user two. So the failed connection is very

7:33likely before we

7:34authenticated. So I could right click here and then add a filter. And then this

7:37is firewall one

7:38reporting on all the logs where the traffic was sourced from 80 user two at

7:43that IP address 10

7:44dot 20 dot 0 dot 1, 0, 2. And the quick traffic would be related to the way

7:47that YouTube is forwarding

7:49the streams of data down to the client. Now it's also interesting to note that

7:53firewall one has

7:54associated this IP address with 80 user two. But if we go back, if we clear the

7:57filters by clicking on

7:58the X here, if we go back to firewall two only and click on okay, there's our

8:03Linux client. But from

8:04the perspective of firewall two, here we have the Linux client again, but it

8:07doesn't say that it's

8:0880 dash user two. And that very likely is because of this firewall one has some

8:12policies in place

8:13requiring authentication identifying who the user is while firewall two doesn't

8:17. And as a result,

8:18that's why the reports coming from firewall one included the ID and the reports

8:22coming from firewall

8:23two didn't. And this will all be more cohesive if if we had a 40 gate security

8:29fabric where, for

8:31example, firewall one was the route. And then firewall two and firewall three

8:35were members of the security

8:36fabric. In fact, in the next video, let's do exactly that and tell these three

8:40firewalls that

8:41they are part of the same security fabric. And then we can compare and contrast

8:44that with the 40

8:45analyzer logs that are coming in. So I'll see you in the next video for exactly

8:48that.

Fortinet Security Fabric and FortiAnalyzer

0:00In this video I like to walk you through what it looks like when we have these

0:02three firewalls

0:03as part of the same security fabric and that way the login information will be

0:06listed duplicates

0:07here at the 4D Analyzer because all three of these devices are part of the same

0:11security fabric.

0:12So to do that let's go ahead and make firewall 1 the root of the security

0:15fabric

0:16and then we'll have firewall 2 and firewall 3 joins. So port 4 will be the

0:20upstream port

0:20that firewall 2 and firewall 3 will use to join this security fabric and if we

0:25come across any

0:26bumps in the road we'll handle them as they come up. Alright so currently we

0:29have firewall 1, 2,

0:31and 3 as three separate individuals who are reporting to 4D Analyzer and let's

0:35go to firewall 1

0:36and we'll go down to security fabric and fabric connectors and currently it's

0:40stand alone here

0:41in the security fabric setup so we'll click that click on edit on firewall 1

0:46and we'll serve as the

0:47fabric root. We'll use port 4 as the port that the downstream firewalls can

0:52join the fabric and

0:53we'll call this our FGT fabric and for the management IP address I'm going to

0:58specify the

0:59management IP address I'm currently using to manage that firewall which is

1:02firewall 1 and we'll

1:03click on okay I also want to make sure under network and interfaces I want to

1:08make sure port 4 is

1:09willing to go ahead and allow security fabric connections. So here under

1:14network interface for

1:15port 4 currently we're allowing security fabric connections to come in

1:18fantastic. So let me go

1:20back to security fabric fabric connectors and currently we are the root and we

1:23're currently

1:24logging to 4D Analyzer so let's go over to firewall 2 and tell it to join the

1:28fabric.

1:29So here in firewall 2 we'll go down to security fabric and then fabric

1:32connectors and here on

1:34the tile for security fabric setup we'll go ahead and click on it click on edit

1:37and we'll say you're

1:38not going to be stand alone you're going to go ahead and join an existing

1:41fabric and I don't need

1:42to worry about an anthropology about other downstream devices beyond it and the

1:46upstream

1:464D gate IP address is 10.123.0.51. So let's confirm that together. So this port

1:524 here

1:53is the IP address of 10.123.0.51 that's the IP address the last octet last

1:59number I used for

2:00all of its interfaces. So that would be the correct IP address for firewall 2

2:04to use to join

2:06the root and become part of the 4D gate security fabric. So for a single sign-

2:11on I'm going to set

2:11that to manual click on okay and it says joining an upstream device will cause

2:15this device's automation

2:16configuration to be discarded and because I haven't set up any animation yet

2:20that's okay and we'll

2:21click on okay all right and then we'll go to firewall 3 and we'll do a similar

2:24thing we'll go to security

2:25fabric fabric connectors and then here for security fabric setup we'll click

2:29that click on edit and

2:31then we'll specify that we wanted to join the fabric as well. So we're going to

2:33join an existing

2:34fabric and that's the upstream slash firewall 1's IP address of 10.123.0.51.

2:39For SAML settings

2:40let's go ahead and do manual and then click on okay. Again this warning is that

2:44any device

2:45automation configuration will be discarded that's fine because we haven't

2:47configured any yet and

2:49I'll click on okay. So now these three firewalls firewall 1 firewall 2 and

2:52firewall 3 are part of

2:54the same security fabric. Another interesting note is that if we hadn't yet had

2:57firewall 2 and

2:58firewall 3 sending logging over to 40 analyzer by joining the security fabric

3:03where firewall 1 was

3:04already sending over to the 40 analyzer firewall 2 and firewall 3 would also

3:07have incorporated the

3:09sending of messages over to 40 analyzer and once again we'd have to go to 40

3:12analyzer to

3:13specify that we want to allow those inbound connections as authorized devices

3:18and as we go

3:18back to firewall 2 and firewall 3 oh we have to add firewall 1 specify that we

3:25need to authorize

3:26firewall 2 and firewall 3 to join the security fabric. So back at firewall 1 we

3:30need to authorize

3:31firewall 2 and firewall 3 to join so let's go ahead and click on the link there

3:35and then click on firmware

3:36and registration which takes us to system firmware and registration and then we

3:40can go ahead and

3:40take firewall 2 and firewall 3 and with them both selected we can click on

3:45authorize. So now those

3:46two firewalls are authorized to join this fabric. So now if we go back to

3:50firewall 2 it's showing

3:51as authorized and same thing for firewall 3 it's also showing as authorized and

3:55the benefit of having

3:57these 40 gates as part of the same security fabric is that now as they're all

4:01sending logs over to

4:02the 40 analyzer the 40 analyzer can logically treat them all as one device or

4:08one entity and can help

4:09reduce duplicates. So for doing for example IDS here, IPS here or an anti-mal

4:14ware here and maybe

4:16other security measures here all that log information is going to be sent over

4:20and correlated here at

4:21the 40 analyzer. So we won't miss anything but at the same time we won't have

4:25duplicate information

4:26for the same exact event coming from two different firewalls. Because the 40

4:29analyzers treat the

4:30security fabric as one larger logical device. So back at 40 analyzer now if we

4:35go to device manager

4:36it's now showing us that as part of this FGT fabric it includes firewall 1

4:42firewall 2 and firewall 3

4:44as part of that same security fabric and this one up here is the branch

4:48firewall off on the right

4:49hand side of our topology.

Working with Logs and FortiView

0:00So now that we have all of our data, log and event information sent over to the

0:0440 analyzer,

0:05the next thing we should take a look at is how to actually work with those logs

0:09that are sitting

0:10here at the 40 analyzer. And one of the challenges with 40 analyzers is that

0:14there's more than just

0:15one way to look at and search for logs and events that are happening. So I'm

0:20going to start off with

0:21basic old logs that are being sent from the 40 gates over to the 40 analyzer

0:25and give you some

0:26examples in action of looking for and working with logs. So to start off, I'm

0:30going to log back

0:31into 40 analyzer and click log in. And also while we're right here at the

0:35initial steps for the 40

0:37analyzer, let me also walk you through how we could change a few settings

0:40should we need to.

0:41So right here, we have this widget for system information. I'll go ahead and

0:44make that bigger.

0:45So there's the host name, the serial number, the platform, the version, and how

0:49long it's been up.

0:49So if we wanted to use administrative domains, what we would do is click right

0:53here, boom,

0:54and enable administrative domains. That way, various firewalls and various Vd

0:59oms could be put into

1:00separate administrative domains. And that way you could have four or five

1:03different administrators

1:04responsible for different parts of the network. And you wouldn't have one giant

1:08blob of aggregated

1:09data you could segment it with administrative domains. So that's how you enable

1:13it right here.

1:14And then when you log on, you'd log on to a specific administrative domain. So

1:18I'm not going to enable

1:19that yet. So I'll click on cancel there. The second thing I want to share with

1:22you that we talked

1:22about in the overview was the operation mode. So if we're in analyzer mode,

1:26which is the default,

1:27that means we can run the reports from here, we can dig into the details of the

1:31logs, do everything.

1:32And that's the basic way we think about a 40 analyzer. However, if you want

1:35this device to be a collector

1:37as an intermediate to collect the login information and to forward them off to

1:40another 40 analyzer,

1:41we click that button right there to tell this 40 analyzer to be in collector

1:44mode. So I'm going

1:45to leave it in analyzer mode. So I'll click on cancel there. But I also want to

1:48share with you

1:49how to do that. So go ahead and restore that to its normal size. And let's just

1:52confirm real quick

1:53with device manager that we have all of our 40 gates reporting, which they are

1:58fantastic.

1:58The branch is by itself. And then as part of our fabric, we have firewall one,

2:02two, and three. So

2:04let's start off with log view. Now there's a thing called 40 view as well,

2:07which gives us like a

2:08summarized grouping of information we'll cover that separately later. But let's

2:12start off with

2:13log view. And then let's go to 40. So when click around 40 gate from our

2:16previous video, I had

2:18left this at firewall to so we go ahead and let me go ahead and select all

2:21devices, click on okay.

2:23And then if we want to also we can click on refresh, if we thought there might

2:26be new data is coming

2:27in. So this is all the logs from all of the reporting, 40 gate devices. Now

2:31currently we're

2:32looking at traffic logs as identified by this tab being selected. But there's

2:36also logs that we

2:36could look at regarding security. And there's also logs regarding events. So if

2:40we go to security,

2:41there's options for these security logs. And there's also events for these

2:45types of events.

2:46So right now we're just looking at traffic logs because this is selected. Now I

2:49've also noticed

2:50that on various different versions of 40 analyzer, they change the screens a

2:54little bit from time

2:55to time. And that's okay. So I'm gonna give us a little more real estate by

2:58collapsing the left

2:59hand column. So we're under log view, 40 gate, I'll go ahead and collapse that

3:02and that'll give us a

3:03little more room to work here. Now in a slightly older version of 40 analyzer,

3:07they had a little

3:07icon for a wrench for tools. But now we have an option called more. And that

3:12can give us these

3:12additional options. So if we click on more here, we can go to real time log.

3:16And with real time log,

3:17it's going to push the logs as they come in. So you're gonna see updates as

3:21those computers on the

3:22network are generating traffic and going through the firewall. Now even in real

3:26time view here,

3:27if we want to pause it, we can use this pause icon right here, simply pause it.

3:31And that would

3:31keep it from scrolling and moving until we clicked on go again. Or if we go to

3:36the more and go to

3:37historical log, that's just going to show us what's there without refreshing

3:41automatically. However,

3:42even here with historical log, if we want to click on refresh, that'll cause

3:46the refresh to

3:46happen. So we can see the latest and greatest information. And then for any of

3:49these logs,

3:50we could double click on it to get more information regarding that specific log

3:53event,

3:54including the firewall that reported it, the source IP address of the device,

3:57where that traffic

3:58came into the firewall on port four, the user ad dash user one, and also where

4:02they were going

4:04and the activity associated with that in the application recognized with HTTPS.

4:08And a protocol

4:09six, that's the number for TCP has information on the duration and number of

4:13packets and so forth.

4:14And as we continue to scroll down, additional information on the authentication

4:18server used

4:18to identify that user, which is right there. Also the centralized source net

4:22rule that it went

4:23through and the actual name of the policy that permitted that traffic to go

4:26through. So I'll go

4:27ahead and close that now. Another option that we have is that we can actually

4:31look at these logs

4:32in a raw format, not formatted. So to do that, we click on more. And then from

4:37the dropdown,

4:37we can go ahead and select raw log, or if you want to see the formatted logs

4:41again,

4:41we could go back to more and select formatted log. Now also, as we look at this

4:45traffic log,

4:46we're currently looking at all devices. And it's also showing us for any time,

4:51we're not putting a

4:52date range, for example, we could say we want to look for traffic logs within

4:55the last, for example,

4:57seven days, or we could do a custom look up, we say, you know what, I want it

5:01between start time of

5:03January 1st, 1970, all the way to July 20th, 2025, click on Okay. And then it

5:09would only show us the

5:10logs in that range, which based on the state, that's everything going way, way

5:14back. So we asked

5:16for traffic, for example, in the last five minutes, we could select that. And

5:19that would show us only

5:20the last five minutes, in this case, of traffic logs, and it was here, there's

5:24only four pages,

5:25where if we said, you know what, let's take a look at the last seven days, then

5:28we have a lot more

5:29pages to deal with. All right, I'm gonna go to page one, I'm gonna go ahead and

5:33specify for this

5:35anytime, again, showing the logs for all devices for all time. Now, in addition

5:39to looking at the

5:39traffic logs, we can also look at these security logs. So we have quite a few

5:43options. Now, one

5:44thing you'll discover on a new 40 analyzer is that if it hasn't seen, for

5:48example, security

5:50information security logs regarding antivirus or IPS or application control,

5:54etc, they mean

5:55that show up here. So it doesn't mean it's broken or you're lacking a license.

5:58It simply means that

6:00it doesn't have any in the logs yet that can show you. So if we go to summary,

6:05this is going to show

6:05us the widgets for antivirus web filter SSL, DNS queries, and also take a look

6:11at the time it set

6:12is for the last hour. So if we said, you know what, let's go ahead and say last

6:17, how about last three

6:19weeks, then it's going to put that filter. And now it's going to include

6:21additional information,

6:22because we're asking it to look at a longer period of time. So there's an

6:25incident or something

6:26happened, you want to narrow it down to a narrow range of time, we could do it

6:30right here. So now

6:32we have an antivirus file that was seen, we have some web filter events DNS

6:36queries, we have

6:38application firewall and SSL events as well. And if you wanted to narrow this

6:41down, we could go

6:42ahead and say, you know, let's take a look at just web filter events. So it

6:46looks like we have some

6:47policies in place that are monitoring traffic, but it looks like everything is

6:51being allowed

6:52through. So if we wanted to right click here, I'm passed through and say, you

6:55know what,

6:55let's go ahead and let's put a filter in place where the action is not passed

7:00through, then we

7:00could go ahead and see blocks. So here are the 123456789 blocks that have

7:06happened based on web

7:08filtering on the 40 analyzer coming from any possible device. So we could drill

7:12down into one

7:12of these, for example, let's go ahead and drill down into this one right here,

7:16we'll just go

7:16ahead and double click on it. And if we look at the details, it'll tell us the

7:20action of blocked

7:21right there. It's also indicating here why it was blocked because of a web

7:26filtering policy,

7:27denying access to any categories of websites that are based on alcohol. Where

7:31if we take a look at

7:32this one right here and click on it, this was also blocked. There's the URL is

7:35trying to go to,

7:36which is a test malware site. And the reason for that it was another category

7:40of malicious websites.

7:41So the idea I want to share here is that we can get very granular with what we

7:45want to look at,

7:46where it's coming from, including what ranges of time we want to look at. So

7:50let's also have a

7:51little fun with this. Let me go ahead and remove the filter sitting looking for

7:54just the blocked.

7:55So I'm looking at web filter activity, because that's what's selected here from

7:58all devices,

7:59any possible time. And let's go back to summary. And let's take a look at the

8:03widget here for

8:03web filter. So if we look at web filters, scroll down, wow, look at this proxy

8:07avoidance. So if

8:09we have policies in place that are supposed to not allow customers to try to

8:14bypass our proxies,

8:15it appears here, based on proxy avoidance and the action of pass through, it

8:19appears here that

8:20we have failed because we have some proxy avoidance, but we have pass through

8:25and 307 in the count field

8:27here. So we click on proxy avoidance, it automatically puts a filter in where

8:31the action is passed

8:32through category description is proxy avoidance. And then we can take a look at

8:35what's going on,

8:36including who's doing it. So looks like user to here, has a whole bunch of

8:41proxy avoidance

8:43websites they've been going to. And that would be absolutely something we'd

8:47want to look into.

8:48So if it's a problem with our policy, we don't have fix our policy to specify

8:51that we don't want

8:52to just allow that traffic, we want to go ahead and block it if the customer is

8:55trying to go to

8:56proxy avoidance types of websites. So if we grab one of these, let's go ahead

9:00and let's grab this

9:01right here, I'll just double click on it to bring it up. As we scroll down, it

9:05's 80 user two at this

9:06IP address 1020 0.102 that was doing it. As we continue to scroll down, the

9:11action was passed through

9:13and the profile is called monitor all. And that monitor all profile, which is

9:17associated with

9:17the security policy is allowing proxy avoidance to go through. And as we

9:22continue to scroll down,

9:23here's the actual URL that the client was going to. So as a test of that, let's

9:27right click that

9:28and copy that. Let's go back to PC to his computer, let's open up a browser and

9:33just confirm we can

9:34still get there. So I'll go ahead and put that URL in and a proxy.com. So here

9:38's where testing

9:39that it's being allowed. So if we wanted to correct that, we'd want to go back

9:42to the policy and correct

9:43it. So if we scroll up, so it's HQ firewall one, and if we scroll down a little

9:47bit, and it's a

9:48profile called monitor all that's using. So if we don't want to monitor all,

9:51and we want to start

9:52blocking on proxy avoidance types of websites, we could either replace that

9:57profile with a profile

9:58that starts blocking, or we can modify that profile. So let's go back to

10:01firewall one. So here at firewall

10:03one under security profiles web filter, there's the profile right there. Let's

10:08go ahead and edit it.

10:09Currently shows it's being used. If we click that, it'll show us where it's

10:12being used in the

10:13end out with LDAP authentication. Great, great, great. So let's go ahead and

10:17modify this profile

10:19for web filtering. So I'm going to double click on it to edit it. And although

10:22it'll still be called

10:23monitor all, we'll go down to proxy avoidance and specify that we want to go

10:26ahead and do a block

10:27instead of just monitor, click on OK. And because that profile is being used by

10:32the policy,

10:32that client should no longer be able to go to proxy avoidance websites. So I'll

10:37go ahead and

10:37grab that URL, close the browser, and let's try it again. So we'll open up a

10:42browser, right click,

10:43paste and go. And this time says not not not gonna happen. Now in addition to

10:49us fixing that

10:49problem, if that was a security violation for our company, we're also going to

10:52have that logged

10:53information at the 40 analyzer, because firewall one and the other firewalls

10:57are all saying their

10:58information over to 40 analyzer. So if we go back to our 40 analyzer, and let's

11:02go ahead and say for

11:03web filtering, let's go ahead and look at the last five minutes, and I still

11:06have the filter in place

11:07for proxy avoidance, let me go ahead and clear off that filter. And right there

11:11, we have our blocks.

11:12Now another way of finding that would be to go ahead and say, you know what, I

11:14want to find

11:15everything that's not passed through. So put that filter in place, and that

11:18will show us those two

11:19blocks and those happen in the last five minutes. Here's another example of

11:22using the same technique

11:23I'm going to go ahead and specify I want to go ahead and use any time range. I

11:28'm also going to click on

11:28the X here to remove the filter for action doesn't equal pass through. And here

11:33in security, let's

11:33go down to application control. So if we scroll to the right a little bit, here

11:36's our applications,

11:37in fact, let me drag that over here a little bit further, so we can see it

11:41without having to scroll

11:42and scroll down. So regarding application control, let's say we want to find

11:46any log entries regarding

11:48social media, you can click on add filter, and then we go down to application

11:53category, and then over

11:54to the right, we can then go ahead and specify equals, and then we can have in

11:57social media,

11:58and then click on apply, and that'll put a filter in where the application

12:01category equals social

12:02media. So instead of having to write it all out, you can actually use the

12:06interface to help you

12:07build it. So here in the application, we have LinkedIn, Facebook, Twitter,

12:10anybody narrow it down to

12:11what's happened more recently, we get once again, specify, for example, last

12:15five minutes. So here

12:16it says no record found, but if we send out traffic to social media site, let's

12:20do it. So here's PC2

12:21and our topology, saying traffic through firewall two and also the firewall one

12:25to get up to the

12:26internet, let's go ahead and go to Fortinet, and let's also go ahead and go to

12:29some social media. So

12:30here's a set of bookmarks for social media, let's go to YouTube, and let's also

12:35go ahead and go to

12:37Facebook, and let's also go to Instagram, Grace, there's YouTube, Facebook, and

12:42Instagram, and we'll

12:43go ahead and close the browser and minimize our client here. And now currently

12:47it says no record

12:48found, but if we do a refresh here by clicking here on refresh, now it's

12:51showing us from the last

12:52five minutes, any application categories of social media, which includes our

12:57Facebook, LinkedIn,

12:58Twitter, and I'm not sure why Instagram is not showing up, they're only

13:00clicking on refresh.

13:01Now there we go, just a little bit of a delay for that information to get all

13:05sorted out here on

13:06the 40 analyzer. So before I leave this, I'm going to go ahead and clear my

13:10filters, and we could also

13:12use this for other types of events as well, DNS, wealth filtering, IPS, etc.

13:16Now another option we

13:17have on the 40 analyzer, I'm going to go ahead and bring back the sidebar here

13:21on the left, is we

13:22also have an option called a Fort review. And think of Fort review as a way of

13:26some views of our data

13:28and our logs that are kind of pre formatted for us. So here under Fort review,

13:31I'm going to go

13:32ahead and click here on threats. Now by default, it's showing us the last week,

13:36I'm going to go ahead

13:38and I'm going to say custom, because a few days ago, I generated some traffic.

13:45So we have something to

13:45look at here. So here under 40 view threats, top threats, my custom time frame

13:49is from 713 all the

13:51way to 720 of this year 2025. Or I could go ahead and say, you know, let's take

13:56a look at the last,

13:57let's say three weeks that'll cover us as well. And so I had a lot of fun not

14:00getting in generating a

14:02lot of events that would show up here as well. So we're going to these top

14:05threats, we can click

14:06here on add filter, and we can go to, for example, threat level. And then with

14:10threat level selected,

14:11we go ahead and say equal. And we could go ahead and say, I only want to see

14:14the critical threat

14:15levels. So the critical selected, we click on apply, and that's going to be a

14:18filter in place to only

14:20show us where the threat level is critical. And that's based on the data here

14:24from the last three

14:25weeks. Or if we want to see the threat level of high, we could go ahead and

14:29remove that filter,

14:30click on add filter again, go down to threat level, and say, I want to see the

14:34high and click on

14:36apply. And this time it's going to show us just the threat level of high. And

14:40if there's a CBE

14:41ID associated with that, you could also click to research that or go on a

14:45filter on a specific

14:46threat, we could, for example, right click on that threat. And from the sub

14:49menu select threat

14:50equals that exact threat. And that would filter out the where it's threat level

14:54high, and the exact

14:55threat is that one. And we could double click on this to look at more details

14:58regarding it. So

14:59there's the source user IP address coming into the firewall and the WAN1

15:03interface. There's the

15:04threat score and the bytes received. And fortunately, this was blocked as

15:08indicated by the yellow right

15:09here. Now, because this was blocked, let's go back and make clear the filters.

15:12And let's take a look

15:13at examples something else that was allowed to go through. So we're going to

15:16top threats,

15:16and go ahead and clear the filters. And I have searched down here for some blue

15:22icons, which means

15:23that traffic was allowed to go through. And let's go ahead and select this one

15:26right here. So I'm

15:27going to say threat equals that one, which puts that filter in for us. And then

15:31I double click on

15:31this entry is putting a filter in place. And then for more detail, we just

15:35continue to double click.

15:36So here is detail about it regarding the 48, which was firewall one, the source

15:41and destination

15:41information and the action, which was allowed. And that was before we changed

15:46the profile to

15:47not allow proxy avoidance. So if we brought our client back in, and we'll open

15:52up a browser,

15:53and we'll go to proxym.com again, our attempt to impress enter, that should be

15:58denied. And also,

16:00that new information will be sent over to the 40 analyzer, where we can now see

16:04it in the logs as

16:04well. So let me go ahead and close that browser, even minimize that, I go back

16:08to log view,

16:09I go back to source, let me go back to top threats and refresh here. And now we

16:13have an update. So now

16:14regarding proxym.com, if we double click on that, we have some that was allowed

16:18and some that was

16:19blocked. And that's being reflected right here. And one other item I want to

16:22share with you here in

16:2340 view is this section down here, these are called monitors under this line

16:27right here. So if we

16:29click on threats and events under the 40 view section, currently, it's set up

16:32for the last week. Let me

16:33go ahead and say the last, let's go ahead and say the last three weeks, all

16:37devices. And I'll let

16:38this refresh. This is going to show us our threats in a map view. So it's

16:43presuming we have our

16:44firewall set up as far as the location of those firewalls correctly as part of

16:4840 analyzer. And

16:50this is showing us our threat map in an animated fashion. You can also control

16:54the replay rate,

16:54then has a top threat destinations. And let me go ahead and make that full

16:58screen. There we go.

16:59So it was small enough where it wouldn't draw it. So here it's showing us the

17:02traffic for our top

17:03threat destinations. So I'm launching it from here. I have to be in Las Vegas,

17:08Nevada, and a lot of

17:09the attacks that I simulated and generated, we're going to United Kingdom and

17:14Spain and Germany and

17:16Indonesia and India. That's a great way to visually see our traffic flows. Go

17:21ahead and minimize that.

17:22And as we can just scroll down, we also have our top threats right here. And

17:25here it's currently

17:26sorted by threat level, but we could also sort it based on threat score. And as

17:30we scroll down,

17:30here's the top threats by weight and count right here. And then if we continue

17:33to scroll down,

17:34here's the top virus instance over time. And I only did it once. It was right

17:38here. So if you

17:38had lots of virus incidents, you could go ahead and say instead of saying most

17:41recent, you could

17:41also say most detected. So I'm going to go back to most recent. So with the

17:45four of you, it's some

17:46really clever, pre-prepared ways of viewing what's happening on your networks

17:52by using 40 analyzer

17:53to give us that overall view of what's happening. And if there's a widget that

17:57you don't want,

17:57you can go ahead and simply remove it by using the drop down here and saying

18:01remove. If you change

18:02your mind, you can always add it back by clicking on add widget and then add

18:06the widget back in,

18:07just like that. And here in the top threats by weight and count, you can also

18:10hover to identify

18:11what the event was. So that was a critical threat. Again, here in the kind of

18:16reddish orange color.

18:17And then down here, we have proxy avoidance, which was a medium threat. And

18:21also with the

18:21color coding of yellow versus blue, what was allowed, what was not allowed.

FortiAnalyzer Scenario

0:00To wrap up this section on the fundamentals and introduction to using 40 Analy

0:04zer,

0:04I'd like to pose a customer scenario and here it is. The customer is

0:08considering using a 40

0:09Analyzer in their Fortinet based network. They have a few questions for us

0:13before they pull the trigger.

0:15So here's the questions. How does the 40 Analyzer, I'll put Faz for short there

0:19,

0:19how does the 40 Analyzer store the log and event data? And then secondly, does

0:23the 40 Analyzer

0:24reduce duplicate log and event entries and how does it do that? So here's what

0:29I love you to do.

0:29I'd like you to pause the video at this point, give those two questions some

0:33thought. And then

0:34when you're ready, click on resume and let's review that together.

0:37All right, so regarding how does the 40 Analyzer store the log and event data?

0:44It uses a flavor of SQL, structured query language, effectively a database to

0:50sort and keep track of

0:51all the log entries that it receives. And then secondly, does the 40 Analyzer

0:54reduce duplicate

0:55log and event entries? And if so, how? Well, the way it does that is if we have

1:01a group of 40

1:03gate firewalls that are part of the same security fabric. And by doing that, it

1:07can logically treat

1:08those 40 gates as like one grouping or family, and it will reduce the duplicate

1:13entries. So Firewall

1:142 is doing IPS functions and Firewall 1 is doing filtering based on application

1:20types or categories

1:21of websites. All that information regarding what's happening is going to be

1:25consolidated here at

1:26the 40 Analyzer to give us a better picture and reduce all the duplicates. So

1:31that way, if it's

1:31just traffic, for example, going from this Windows computer out to the public

1:34internet. And let's

1:35imagine that traffic is allowed by all the firewall policies in place. The 40

1:39Analyzer,

1:39because these devices are on the same security fabric is going to reduce

1:43unnecessary duplicate

1:44entries. And that's how it does it by leveraging the 40 gate security fabric.

1:48So thanks for joining

1:49me in this set of videos as we've taken a first look at this wonderful tool

1:52called the 40 Analyzer.

1:54And I look forward to seeing you, my friend, in another set of videos very,

1:57very soon. Until then,

1:58I hope this has been informative, and I'd like to thank you for viewing.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need Fortinet FortiAnalyzer?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo