What’s new in FortiOS Version 4.0 MR1 Reliable syslog
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903 83
http://docs.fortinet.com/ • Feedback
Reliable syslog
Reliable syslog protects log information through authentication and data encryption and
ensures that the log messages are reliably delivered in order. FortiOS 4.0 MR1
implements the RAW profile of RFC 3195. This feature is configurable only in the CLI.
Syntax
These are global settings.
config log syslogd setting
set reliable {enable | disable}
end
config log syslogd2 setting
set reliable {enable | disable}
end
config log syslogd3 setting
set reliable {enable | disable}
end
In each VDOM, you can enable reliable syslog as part of an override of the global syslog
settings. See “Support for per-VDOM FortiAnalyzer units or syslog devices” on page 79.
conf log syslogd override-setting
set reliable {enable | disable}
end
By default, reliable syslog is disabled.
Web filtering combined block/exempt list
FortiOS Version 4.0 MR1 combines the Web Content Block and Web Content Exempt lists
into one list. Go to Web Filter > Web Content. As before, you first create a list and then
add entries. The new entry dialog box looks like this:
Figure 9: New combined web filter content block/exempt list entry
Action Select one of:
Block — If the pattern matches, the Score is added to the total for the web page.
The page is blocked if the total score of the web page exceeds the web content
block threshold defined in the protection profile.
Exempt — If the pattern matches, the web page will not be blocked even if there
are matching Block entries.
Pattern Enter the content pattern. Web content patterns can be one word or a text string
up to 80 characters long.
For a single word, the FortiGate checks all web pages for that word. For a phrase,
the FortiGate checks all web pages for any word in the phrase. For a phrase in
quotation marks, the FortiGate unit checks all web pages for the entire phrase.