Logging, FortiAnalyzer, FortiManager & Automation

FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)

مقصدObjectiveObjective

اس لیب میں آپ لاگز کو FortiAnalyzer (اور syslog) پر فارورڈ کریں گے، FortiGate کو FortiManager سے رجسٹر کریں گے، آٹومیشن اسٹچز دیکھیں گے اور REST API ایڈمن بنائیں گے۔Is lab mein aap logs ko FortiAnalyzer (aur syslog) par forward karenge, FortiGate ko FortiManager se register karenge, automation stitches dekhenge aur REST API admin banayenge.In this lab you will forward logs to FortiAnalyzer (and syslog), register the FortiGate with FortiManager, explore automation stitches, and create a REST API admin.

آسان مثالSimple AnalogySimple Analogy

لاگنگ اور سینٹرل مینجمنٹ ایسے ہیں جیسے سوسائٹی کا CCTV کنٹرول روم اور ہیڈ آفس: ہر گیٹ کا کیمرہ (لاگ) ایک کمرے میں دیکھا جاتا ہے (FortiAnalyzer)، اور سب گیٹس کے اصول ایک دفتر سے اپ ڈیٹ ہوتے ہیں (FortiManager) — ہر گیٹ پر جانے کے بجائے۔Logging aur central management aise hain jaise society ka CCTV control room aur head office: har gate ka camera (log) aik kamre mein dekha jata hai (FortiAnalyzer), aur sab gates ke usool aik daftar se update hote hain (FortiManager) — har gate par jane ke bajaye.Logging and central management are like a society's CCTV control room plus a head office: every gate's camera (log) is watched in one room (FortiAnalyzer), and all gates' rules are updated from one office (FortiManager) instead of visiting each gate.

سیٹ اپLab SetupLab Setup

fg-03 والی FortiGate استعمال کریں۔ FortiAnalyzer 192.168.20.10 پر، syslog سرور 192.168.20.11 پر، FortiManager 192.168.20.12 پر (EVE-NG لیب IPs)۔fg-03 wali FortiGate istemal karen. FortiAnalyzer 192.168.20.10 par, syslog server 192.168.20.11 par, FortiManager 192.168.20.12 par (EVE-NG lab IPs).Use the fg-03 FortiGate. FortiAnalyzer at 192.168.20.10, syslog server at 192.168.20.11, FortiManager at 192.168.20.12 (EVE-NG lab IPs).

اقداماتStepsSteps

Step 1

لاگز FortiAnalyzer کو بھیجیں۔ FAZ لاگز کو طویل مدت کے لیے رکھتا ہے، رپورٹس بناتا ہے اور فارنزکس میں مدد کرتا ہے — ہر اصلی ڈیپلائمنٹ کے لیے ضروری۔Logs FortiAnalyzer ko bhejen. FAZ logs ko taweel muddat ke liye rakhta hai, reports banata hai aur forensics mein madad karta hai — har asli deployment ke liye zaroori.Send logs to FortiAnalyzer. FAZ stores logs long-term, builds reports, and helps with forensics — essential for any real deployment.

config log fortianalyzer setting
    set status enable
    set server 192.168.20.10
end

🖱️ Log & Report > Log Settings > FortiAnalyzer میں کنفیگر کریں۔Log & Report > Log Settings > FortiAnalyzer mein configure karen.Configure under Log & Report > Log Settings > FortiAnalyzer.

Step 2

دوسری منزل کے طور پر syslog سرور شامل کریں — SIEM انٹیگریشن اور FortiAnalyzer unreachable ہونے پر بیک اپ کے لیے مفید۔Doosri manzil ke taur par syslog server shamil karen — SIEM integration aur FortiAnalyzer unreachable hone par backup ke liye mufeed.Add a syslog server as a second destination — useful for SIEM integration and as a backup when FortiAnalyzer is unreachable.

config log syslogd setting
    set status enable
    set server 192.168.20.11
end

🖱️ Log & Report > Log Settings > Syslog میں کنفیگر کریں۔Log & Report > Log Settings > Syslog mein configure karen.Configure under Log & Report > Log Settings > Syslog.

Step 3

مرکزی مینجمنٹ کے لیے FortiGate کو FortiManager سے رجسٹر کریں۔ پھر FMG کئی FortiGates پر ایک ساتھ پالیسیز اور فرم ویئر پش کر سکتا ہے — اسکیل پر مینیج کرنے کی کنجی۔Markazi management ke liye FortiGate ko FortiManager se register karen. Phir FMG kai FortiGates par aik saath policies aur firmware push kar sakta hai — scale par manage karne ki kunji.Register the FortiGate with FortiManager for central management. FMG can then push policies and firmware to many FortiGates at once — the key to managing at scale.

config system central-management
    set mode normal
    set type fortimanager
    set fmg 192.168.20.12
end

🖱️ Security Fabric > Settings > Central Management میں رجسٹر کریں۔Security Fabric > Settings > Central Management mein register karen.Register under Security Fabric > Settings > Central Management.

Step 4

آٹومیشن اسٹچز دیکھیں۔ اسٹچ ایک ٹرگر (مثال، مال ویئر ڈیٹیکٹ ہونا یا ہائی CPU) کو ایکشنز (ہوسٹ بلاک کرنا، قرنطینہ، ای میل الرٹ بھیجنا) سے جوڑتا ہے — خودکار انسیڈنٹ ریسپانس۔Automation stitches dekhen. Stitch aik trigger (misal, malware detect hona ya high CPU) ko actions (host block karna, quarantine, email alert bhejna) se jorta hai — khudkar incident response.Explore automation stitches. A stitch links a trigger (for example, malware detected or high CPU) to actions (block the host, quarantine, send an email alert) — automatic incident response.

🖱️ Security Fabric > Automation میں ٹرگرز، ایکشنز اور اسٹچز دیکھیں۔Security Fabric > Automation mein triggers, actions aur stitches dekhen.Explore triggers, actions, and stitches under Security Fabric > Automation.

Step 5

آٹومیشن کے لیے REST API ایڈمن بنائیں۔ پھر اسکرپٹس اور ٹولز ٹوکن سے FortiGate کو پروگرامیٹکلی کنفیگر کرتے ہیں — انفراسٹرکچر ایز کوڈ ورک فلوز کی بنیاد۔Automation ke liye REST API admin banayen. Phir scripts aur tools token se FortiGate ko programmatically configure karte hain — infrastructure-as-code workflows ki bunyad.Create a REST API admin for automation. Scripts and tools then use the token to configure the FortiGate programmatically — the foundation of infrastructure-as-code workflows.

config system api-user
    edit automation
        set accprofile super_admin
        set vdom root
    next
end

🖱️ System > Administrators میں REST API ایڈمن بنائیں (ٹائپ REST API Admin منتخب کریں) تاکہ ٹوکن ملے۔System > Administrators mein REST API Admin banayen (type REST API Admin muntakhib karen) taake token mile.Create a REST API Admin under System > Administrators (choose type REST API Admin) to get the token.

Step 6

ٹیسٹ لاگ جنریٹ کریں اور FortiAnalyzer کنکشن اسٹیٹس کنفرم کریں۔ اصلی لاگز فوراً FAZ کی طرف بہنے لگنے چاہئیں۔Test log generate karen aur FortiAnalyzer connection status confirm karen. Asli logs foran FAZ ki taraf behne lagne chahiye.Generate a test log and confirm the FortiAnalyzer connection status. Real logs should start flowing to FAZ immediately.

diagnose log test
get log fortianalyzer setting status

تصدیقVerifyVerify

FortiAnalyzer میں FortiGate رجسٹرڈ اور لاگز وصول کرتے نظر آنا چاہیے۔ FortiManager میں ڈیوائس مینیجڈ شو ہونا چاہیے۔FortiAnalyzer mein FortiGate registered aur logs wasool karte nazar aana chahiye. FortiManager mein device managed show hona chahiye.In FortiAnalyzer you should see the FortiGate registered and receiving logs. In FortiManager the device should show as managed.

get log fortianalyzer setting status
get system central-management

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ لاگز FortiAnalyzer تک نہیں پہنچ رہے۔Logs FortiAnalyzer tak nahi pohanch rahe.Logs are not reaching FortiAnalyzer.

✅ FAZ IP تک کنکٹیویٹی چیک کریں، کہ لاگ ٹریفک پالیسیز سے الاؤڈ ہے، اور FAZ اسٹیٹس دیکھیں۔ FortiGate پر diagnose log test چلائیں پھر FAZ کے لاگ ریسیو مانیٹر میں دیکھیں۔FAZ IP tak connectivity check karen, ke log traffic policies se allowed hai, aur FAZ status dekhen. FortiGate par diagnose log test chalayen phir FAZ ke log receive monitor mein dekhen.Check connectivity to the FAZ IP, that log traffic is allowed by policies, and the FAZ status. On the FortiGate, diagnose log test then check FAZ's log receive monitor.

⚠️ FortiManager FortiGate ایڈ نہیں کر پا رہا۔FortiManager FortiGate add nahi kar pa raha.FortiManager cannot add the FortiGate.

✅ FortiGate پر fmg IP ویریفائی کریں، دونوں طرف reachability چیک کریں، اور سینٹرل مینجمنٹ موڈ normal ہو۔ FMG اور FortiGate کے ماڈل ورژنز کمپیٹیبل ہونے چاہئیں۔FortiGate par fmg IP verify karen, dono taraf reachability check karen, aur central management mode normal ho. FMG aur FortiGate ke model versions compatible hone chahiye.Verify the fmg IP on the FortiGate, bidirectional reachability, and that central management mode is normal. Model versions on FMG and FortiGate should be compatible.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ FortiManager اور FortiAnalyzer میں کیا فرق ہے؟FortiManager aur FortiAnalyzer mein kya farq hai?What is the difference between FortiManager and FortiAnalyzer?

FortiManager کئی FortiGates کو مرکزی طور پر مینیج کرتا ہے — پالیسیز اور کنفگز پش کرتا ہے۔ FortiAnalyzer ان کے لاگز جمع کر کے اینالائز کرتا ہے — رپورٹس، فارنزکس اور کمپلائنس۔ ایک کنفیگر کرتا ہے، دوسرا نظر رکھتا ہے۔FortiManager kai FortiGates ko markazi taur par manage karta hai — policies aur configs push karta hai. FortiAnalyzer un ke logs jama kar ke analyze karta hai — reports, forensics aur compliance. Aik configure karta hai, doosra nazar rakhta hai.FortiManager manages many FortiGates centrally — pushing policies and configs. FortiAnalyzer collects and analyzes their logs — reports, forensics, and compliance. One configures, the other watches.

❓ FortiGate آٹومیشن کیسے کام کرتی ہے (اسٹچز اور API)؟FortiGate automation kaise kaam karti hai (stitches aur API)?How does FortiGate automation work (stitches and API)?

آٹومیشن اسٹچز کسی ٹرگر (جیسے مال ویئر ڈیٹیکٹ ہونا) پر نظر رکھتی ہیں اور خود ایکشنز چلاتی ہیں (ہوسٹ بلاک کرنا، ای میل بھیجنا)۔ REST API اسکرپٹس اور ٹولز کو FortiGate کو پروگرامیٹکلی کنفیگر کرنے دیتا ہے۔Automation stitches kisi trigger (jaise malware detect hona) par nazar rakhti hain aur khud actions chalati hain (host block karna, email bhejna). REST API scripts aur tools ko FortiGate ko programmatically configure karne deta hai.Automation stitches watch for a trigger (like malware detected) and run actions automatically (block the host, send an email). The REST API lets scripts and tools configure the FortiGate programmatically.