<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>安裝Firewall Analyzer來收集Fortigate防火牆log &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/%E5%AE%89%E8%A3%9Dfirewall-analyzer%E4%BE%86%E6%94%B6%E9%9B%86fortigate%E9%98%B2%E7%81%AB%E7%89%86log/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Fri, 04 Jun 2021 12:44:12 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>安裝Firewall Analyzer來收集Fortigate防火牆log</title>
		<link>https://ailog.tw/lifelog/2021/05/20/firewall-analyzer/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Thu, 20 May 2021 10:00:16 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Firewall Analyzer]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[安裝Firewall Analyzer來收集Fortigate防火牆log]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8290</guid>

					<description><![CDATA[近期因為疫情的關係，很多公司已有採居家上班的狀況，並透過VPN讓使用者可以連線回公司存取公司的資源，但到底哪些 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/20/firewall-analyzer/" class="more-link">閱讀全文<span class="screen-reader-text">〈安裝Firewall Analyzer來收集Fortigate防火牆log〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">近期因為疫情的關係，很多公司已有採居家上班的狀況，並透過VPN讓使用者可以連線回公司存取公司的資源，但到底哪些人有VPN連線進來過，怎麼保留連線紀錄呢?很多中小企業在裝設防火牆時是沒有建立log收集的機制的，小編今天要介紹透過Firewall Analyzer來收集防火牆的VPN資訊。<span id="more-8290"></span></span></p>
<p><span style="font-size: 14pt;">考慮到在企業使用盡量不增加授權的成本，本篇小編會介紹以Linux環境安裝的方式。</span></p>
<p><span style="font-size: 14pt;">Firewall Analyzer官方網頁介紹：</span><br />
<span style="font-size: 14pt;"><a href="https://www.manageengine.com/products/firewall/">https://www.manageengine.com/products/firewall/</a></span></p>
<p><strong><span style="font-size: 14pt;">01、安裝好Linux</span></strong><br />
<span style="font-size: 14pt;">安裝步驟可以參考下列文章：<br />
<a href="https://ailog.tw/lifelog/2021/05/15/ubuntu-20-install/">https://ailog.tw/lifelog/2021/05/15/ubuntu-20-install/</a><br />
</span></p>
<p><strong><span style="font-size: 14pt;">02、下載Firewall Analyzer軟體(30天免費授權)<br />
</span></strong><span style="font-size: 14pt;">Linux 32位元下載網址：<br />
<a href="https://www.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer.bin">https://www.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer.bin</a></span></p>
<p><span style="font-size: 14pt;">Linux 64位元下載網址：<br />
<a href="https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin">https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin</a></span></p>
<p>[直接在Linux系統下載檔案]<br />
指令：<br />
sudo wget https://download.manageengine.com/products/firewall/61794333/ManageEngine_FirewallAnalyzer_64bit.bin<br />
<img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-8292" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01.png" alt="" width="819" height="339" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01.png 819w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01-300x124.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-01-768x318.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p><strong><span style="font-size: 14pt;">03、設定安裝檔成可執行的檔案<br />
</span></strong><span style="font-size: 14pt;">sudo chmod 755 ManageEngine_FirewallAnalyzer_64bit.bin<br />
<img decoding="async" class="alignnone size-full wp-image-8294" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02.png" alt="" width="876" height="113" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02.png 876w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02-300x39.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-02-768x99.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><strong><span style="font-size: 14pt;">04、安裝<strong>Firewall Analyzer軟體</strong><br />
</span></strong><span style="font-size: 14pt;">sudo ./ManageEngine_FirewallAnalyzer_64bit.bin</span><strong><span style="font-size: 14pt;"><br />
<img decoding="async" class="alignnone size-full wp-image-8298" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1.png" alt="" width="798" height="92" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1.png 798w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1-300x35.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-03-1-768x89.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></strong></p>
<p><strong><span style="font-size: 14pt;">05、同意軟體授權</span></strong><br />
按下鍵盤「enter」進入同意相關授權步驟<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8296" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04.png" alt="" width="818" height="158" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04.png 818w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04-300x58.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-04-768x148.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>過程持續按鍵盤「enter」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8299" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05.png" alt="" width="488" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05.png 488w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-05-300x120.png 300w" sizes="auto, (max-width: 488px) 100vw, 488px" /></p>
<p>最後按下「Y」接受授權<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8300" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06.png" alt="" width="742" height="197" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06.png 742w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-06-300x80.png 300w" sizes="auto, (max-width: 706px) 89vw, (max-width: 767px) 82vw, 740px" /></p>
<p>06、是否註冊技術支援服務<br />
本範例選：N<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8301" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07.png" alt="" width="883" height="145" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07.png 883w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07-300x49.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-07-768x126.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>07、軟體安裝路徑<br />
採用預設安裝路徑，按下Enter即可<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8302" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08.png" alt="" width="703" height="194" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08.png 703w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-08-300x83.png 300w" sizes="auto, (max-width: 703px) 100vw, 703px" /></p>
<p>08、設定web連線服務Port<br />
本範例採用預設值：8060<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8303" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09.png" alt="" width="579" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09.png 579w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-09-300x69.png 300w" sizes="auto, (max-width: 579px) 100vw, 579px" /></p>
<p>09、確認安裝資訊<br />
按下「ENTER」繼續安裝<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8305" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10.png" alt="" width="568" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10.png 568w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-10-300x181.png 300w" sizes="auto, (max-width: 568px) 100vw, 568px" /><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8306" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11.png" alt="" width="828" height="195" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11.png 828w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11-300x71.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-11-768x181.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>10、安裝完成畫面<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8307" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12.png" alt="" width="871" height="427" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12.png 871w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12-300x147.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-12-768x377.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>11、將<strong><span style="font-size: 14pt;">Firewall Analyzer安裝成Service型態<br />
</span></strong>cd /opt/ManageEngine/OpManager/bin<br />
sudo sh linkAsService.sh<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8310" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13.png" alt="" width="937" height="382" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13.png 937w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13-300x122.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-13-768x313.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>12、啟動<strong><span style="font-size: 14pt;">Firewall Analyzer軟體<br />
</span></strong><span style="font-size: 14pt;">sudo systemctl start OpManager.service</span><strong><span style="font-size: 14pt;"><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8311" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14.png" alt="" width="703" height="49" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14.png 703w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-14-300x21.png 300w" sizes="auto, (max-width: 703px) 100vw, 703px" /><br />
</span></strong></p>
<p>13、檢查服務Port是否有啟動<br />
ss -an | grep 8060<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8312" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15.png" alt="" width="929" height="67" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15.png 929w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15-300x22.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-15-768x55.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>14、登入Fortigate防火牆設定log server<br />
透過SSH或Console登入，輸入下令指令：<br />
(1)、啟動syslog並指定傳送到Firewall Analyzer主機上，範例中的192.168.5.243為小編的Firewall Analyzer Server IP，請自行更改為自己相對應的IP。<br />
config log syslogd setting<br />
set status enable<br />
set server <span style="color: #ff0000;">192.168.5.243</span><br />
set port 1514<br />
end</p>
<p>(2)、設定要傳送什麼loh內容<br />
config log syslogd filter<br />
set severity information<br />
set forward-traffic enable<br />
set local-traffic enable<br />
set anomaly enable</p>
<p>15、透過瀏覽器登入系統<br />
預設帳號：admin<br />
預設密碼：admin<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8313" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16.png" alt="" width="506" height="479" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16.png 506w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-16-300x284.png 300w" sizes="auto, (max-width: 506px) 100vw, 506px" /></p>
<p>16、點選「Dashboard」→「VPN」即可看到防火牆的VPN相關的狀態<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8316" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-17.png" alt="" width="196" height="265" /></p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8317" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18.png" alt="" width="752" height="360" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18.png 752w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-18-300x144.png 300w" sizes="auto, (max-width: 706px) 89vw, (max-width: 767px) 82vw, 740px" /></p>
<p>17、查看VPN歷史報表<br />
點選「Reports」 → 「VPN Reports」即可觀看VPN的歷史紀錄<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8320" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19.png" alt="" width="299" height="397" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19.png 299w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-19-226x300.png 226w" sizes="auto, (max-width: 299px) 100vw, 299px" /></p>
<p>18、變更系統介面語系<br />
(1)、點選右上角齒輪圖示<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8482" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-22.png" alt="" width="275" height="212" /></p>
<p>(2)、選擇左邊的「Language Selector」，接著選擇右邊的「Chinese(Traditional)繁体中文」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8484" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23.png" alt="" width="439" height="440" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23.png 439w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-300x300.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-150x150.png 150w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-23-100x100.png 100w" sizes="auto, (max-width: 439px) 100vw, 439px" /></p>
<p>(3)、網頁會自動重新整理，接著就可以看到中文網頁了<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8485" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24.png" alt="" width="582" height="170" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24.png 582w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/fw-log-24-300x88.png 300w" sizes="auto, (max-width: 582px) 100vw, 582px" /></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
