NSE4 · Question #410
If you enable the option "Generate Logs when Session Starts", what effect does this have on the number of traffic log messages generated for each session?
The correct answer is C. Two traffic log messages are generated. Enabling the 'Generate Logs when Session Starts' option on FortiGate results in two traffic log messages being generated for each session.
Question
If you enable the option "Generate Logs when Session Starts", what effect does this have on the number of traffic log messages generated for each session?
Options
- ANo traffic log message is generated.
- BOne traffic log message is generated.
- CTwo traffic log messages are generated.
- DA log message is only generated if there is a security event.
How the community answered
(31 responses)- A6% (2)
- C90% (28)
- D3% (1)
Why each option
Enabling the 'Generate Logs when Session Starts' option on FortiGate results in two traffic log messages being generated for each session.
This option specifically enables session start logging, so traffic logs are indeed generated.
By default, one log message is generated at session end; this option adds a second log message at session start, making it two.
When 'Generate Logs when Session Starts' is enabled for a firewall policy, FortiGate generates one traffic log entry when the session initiates and a second entry when the session terminates, totaling two logs per session.
Traffic logging is distinct from security event logging, and traffic logs are generated for sessions as configured, regardless of security events.
Concept tested: FortiGate session start logging
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/708493/firewall-policies-and-logging
Topics
Community Discussion
No community discussion yet for this question.