FortiOS FSSO log messages
There are two types of FortiOS log messages — firewall and event. FSSO related log messages are generated from authentication events. These include user logon and log off events, and NTLM authentication events. These log messages are central to network accounting policies, and can also be useful in troubleshooting issues. For more information on firewall logging, see Enabling security logging on page 87. For more information on logging, see the FortiOS Handbook Logging and Reporting guide.
Enabling authentication event logging
For the FortiGate unit to log events, that specific type of event must be enabled under logging.
When VDOMs are enabled certain options may not be available, such as CPU and memory usage events. You can enable event logs only when you are logged on to a VDOM; you cannot enable event logs globally.
To ensure you log all the events needed, set the minimum log level to Notification or Information. Firewall logging requires Notification as a minimum. The closer to Debug level, the more information will be logged.
To enable event logging:
- Go to Log & Report > Log Settings.
- Under Log Settings, set Event Logging to Customize and select
System activity event | All system-related events, such as ping server failure and gateway status. |
User activity event | All administration events, such as user logins, resets, and configuration updates. |
- Select Apply.
List of FSSO related log messages
Message ID | Severity | Description |
43008 | Notification | Authentication was successful |
43009 | Notification | Authentication session failed |
Testing FSSO
Message ID | Severity | Description |
43010 | Warning | Authentication locked out |
43011 | Notification | Authentication timed out |
43012 | Notification | FSSO authentication was successful |
43013 | Notification | FSSO authentication failed |
43014 | Notification | FSSO user logged on |
43015 | Notification | FSSO user logged off |
43016 | Notification | NTLM authentication was successful |
43017 | Notification | NTLM authentication failed |
For more information on logging, see the FortiOS Handbook Logging and Reporting guide.
Extra filter options for security events
Logon events are detected by the FSSO CA by monitoring the Security Event logs. Additional logon event filters, such as ServiceName and ServiceID, have been implemented so as to avoid instances of conflicting security events, where existing user information could be overwritten.