Step 1: Configure Syslog Destination
You can configure the Syslog server target either through the Web GUI or using the CLI (recommended for custom UDP ports).- GUI (Web Console)
- CLI (Custom Port)
- Go to Log & Report > Log Settings.
- Toggle on Send Logs to Syslog.
- Enter the IP Address/Name of your Syslog server.
- Set Mode to UDP (or leave default if standard port 514 is used).
- Click Apply at the bottom of the page.
The FortiGate GUI configures the default Syslog port (
UDP 514). If you need to use a custom port, use the CLI tab instead.Step 2: Enable Logging on Firewall Policies
Traffic logs are only generated and sent if logging is explicitly enabled on the relevant firewall policies.1
Open Firewall Policies
Navigate to Policy & Objects > Firewall Policy.
2
Configure LAN -> WAN Policy
- Select the outbound rule (LAN to WAN) and click Edit.
- Scroll down to the Logging Options section.
- Enable Log Allowed Traffic.
- Select All Sessions to capture all connections.
- Click OK.
3
Configure WAN -> LAN Policy
- Select the inbound rule (WAN to LAN, e.g., VIPs / Port Forwarding) and click Edit.
- Enable Log Allowed Traffic > All Sessions.
- Click OK.

