Configure FortiNAC
-
Enable the pre-defined Syslog File for the appropriate Fortinet version.
-
In the Administrative UI, navigate to System > Settings > System Communication > Syslog Files
-
If the appropriate Syslog File is not already enabled, highlight the PaloAlto entry, right-click and select Enable
For syslog field definitions, see section Syslog Management of the Administration Guide in the Fortinet Document Library.
-
Modify or create a model for the firewall in the Topology view. The model must contain the IP address Palo Alto uses to send the Syslog messages.
In the Administration UI, navigate to Network > Inventory.
Adding a Firewall Model
-
Right Click on the container desired to add the Firewall.
-
Select Add Device.
-
Input IP, SNMP, and SSH information.
-
Continue with Existing Firewall instructions below.
-
Existing Firewall Models
Modify the existing model if the IP address is the same as the one sending the Syslog messages.
-
Locate the firewall model in the tree.
-
Right-click the model and select Properties.
-
For Incoming Events, click the first drop-down and select either Syslog or Security Events (see next page for field description).
-
In the second drop-down, select PaloAlto Firewall.
-
Click Save.