Communication with FortiAnalyzer for logging
This section applies only if you are sending logs from FortiClient to FortiAnalyzer. If you are not sending logs, skip this section.
Sending logs to FortiAnalyzer requires you enable administrative domains (ADOM) in FortiAnalyzer and add FortiClient EMS to FortiAnalyzer. You can add FortiClient EMS as a device to the FortiClient or Fortinet Security Fabric ADOM in FortiAnalyzer. See the FortiAnalyzer Administration Guide. |
FortiClient supports logging to FortiAnalyzer. If you have a FortiAnalyzer and configure FortiClient to send logs to FortiAnalyzer, you must enable a FortiAnalyzer CLI command and communication between the FortiClient Web Filter extension and FortiAnalyzer requires an SSL certificate.
If you use a public SSL certificate, you only need to add the public SSL certificate to FortiAnalyzer. See Adding an SSL certificate to FortiAnalyzer.
However, if you prefer to use a certificate not from a common CA, you must add the SSL certificate to FortiAnalyzer and push your certificate's root CA to the Google Chromebooks. Otherwise, the HTTPS connection between the FortiClient Chromebook Web Filter extension and FortiAnalyzer does not work. See Uploading root certificates to the Google Admin console.
You must use the FortiAnalyzer CLI to add HTTPS-logging to the allow-access list in FortiAnalyzer. This command is one step in the process that allows FortiAnalyzer to receive logs from FortiClient.
In FortiAnalyzer CLI, enter the following command:
config system interface
edit "port1"
set allowaccess https ssh https-logging
next
end
Adding an SSL certificate to FortiAnalyzer
To add an SSL certificate to FortiAnalyzer:
- In FortiAnalyzer, go to System Settings > Certificates > Local Certificates.
- Click Import. The Import Local Certificate dialog appears.
- In the Type list, select Certificate or PKCS #12 Certificate.
- Beside Certificate File, click Browse to select the certificate.
- Enter the password and certificate name.
- Click OK.
Selecting a certificate for HTTPS connections
To select a certificate for HTTPS connections:
- In FortiAnalyzer, go to System Settings > Admin > Admin Settings.
- From the HTTPS & Web Service Certificate dropdown list, select the certificate to use for HTTPS connections, and click Apply.