Skip to main content
This guide covers how to forward FortiGate traffic logs (WAN to LAN and vice versa) to a specific IP address and UDP port using Syslog, via both the GUI and CLI.

Step 1: Configure Syslog Destination

You can configure the Syslog server target either through the Web GUI or using the CLI (recommended for custom UDP ports).
  1. Go to Log & Report > Log Settings.
  2. Toggle on Send Logs to Syslog.
  3. Enter the IP Address/Name of your Syslog server.
  4. Set Mode to UDP (or leave default if standard port 514 is used).
  5. Click Apply at the bottom of the page.
The FortiGate GUI configures the default Syslog port (UDP 514). If you need to use a custom port, use the CLI tab instead.

Step 2: Enable Logging on Firewall Policies

Traffic logs are only generated and sent if logging is explicitly enabled on the relevant firewall policies.
1

Open Firewall Policies

Navigate to Policy & Objects > Firewall Policy.
2

Configure LAN -> WAN Policy

  1. Select the outbound rule (LAN to WAN) and click Edit.
  2. Scroll down to the Logging Options section.
  3. Enable Log Allowed Traffic.
  4. Select All Sessions to capture all connections.
  5. Click OK.
3

Configure WAN -> LAN Policy

  1. Select the inbound rule (WAN to LAN, e.g., VIPs / Port Forwarding) and click Edit.
  2. Enable Log Allowed Traffic > All Sessions.
  3. Click OK.

Step 3: Verify Traffic Output

To verify that Syslog UDP packets are actively being sent from the FortiGate, run a packet trace via CLI: