Managing Devices Flashcards

1
Q

Device Registration States

A

Registered: Authorized to store logs on FAZ
Unregistered: Requesting to store logs on FAZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How to register device

A

Initiate from FAZ or remote device
stage devices on FAZ by prepopulating information
Add individual devices or a Security Fabric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Pre-Shared Key method

A

Only usable for FGTs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Logs are Collected from FortiGate?

A

Logs - Traffic, Event, Security
DLP Archive
Quarantine
IPS Packet Log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Command to see devices and IPs connecting to FAZ

A

diagnose test application oftpd 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ADOM and Device list commands

A

diagnose dvm adom list - what adoms are enabled and configured
diagnose dvm device list - what devices or VDOMs are currently registered or unregistered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Troubleshooting commands

A

execute ping
diagnose debug application oftpd 8 - Is FAZ receiving logs?
show log fortianalyzer settings - Is FGT configured for remote logging to FAZ, is FAZ source IP set on FGT?
show log fortianalyzer filter - Are logging filters for logs sent to FAZ on FGT enabled?
diagnose log test - is FGT capable of generating logs?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Troubleshooting traffic to FAZ

A

Run sniffers on both devices.
diagnose sniff packet <interface> <filter> <level> <count> <timestamp></timestamp></count></level></filter></interface>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Steps to Troubleshooting Communications

A

Debug the oftpd process
Generate test logs on FGT
Verify logs are received

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Moving Registered Devices between ADOMs

A

Don’t if you don’t have to.
Can move them after registration. (Restricted to Super_User Admins)
Don’t need to create a new ADOM if you upgrade FGT firmware(not necessary to seperate ADOMs by FortiOS version)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

After moving a device

A

Ensure Disk quota has enough space

When you move a device, only the archive logs are migrated to new adom. Analytics logs stay in the old one until you rebuild the databases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Adding a FGT HA cluster

A

FAZ automatically discovers if a FGT is in a cluster. If registered to FAZ before forming the clust, add them manually together

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How to get Analytics Logs in New ADOM after Moving a device?

A

execute sql-local rebuild-adom <new-adom-name></new-adom-name>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How to get rid of Analytics Logs of new device in Old ADOM?

A

execute sql-local rebuild-adom <old-adom-name></old-adom-name>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does FAZ distinguish FGT cluster member logs?

A

FAZ distinguishes them by serial numbers from log message headers.

Each device generates its own logs, separated by serial numbers of devices. The primary is responsible for sending logs to FAZ.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly