Allowing Branch to access the FortiAnalyzer
- On Branch, go to Policy & Objects > Addresses and create an address for the FortiAnalyzer.
Enable Static Route Configuration.
- Go to VPN > IPsec Tunnels and create a Phase 2 to allow traffic between the Branch tunnel interface and the FortiAnalyzer.
- Go to Network > Static Routes and create a route to the FortiAnalyzer.
- On External, go to Policy & Objects > Addresses and create an address for the FortiAnalyzer.
- Go to VPN > IPsec Tunnels and create a Phase 2 to allow traffic between the FortiAnalyzer and the Branch tunnel interface.
- Go to Policy & Objects > IPv4 Policy and create a policy to allow traffic from the VPN tunnel to the FortiAnalyzer.
Enable NAT for this policy.
- On Branch, go to Security Fabric > Settings.
In the FortiAnalyzer Logging section, an error appears because Branch is not yet authorized on the FortiAnalyzer.
- On the FortiAnalyzer, go to Device Manager > Unregistered.
Select Branch and then select +Add to register Branch.
- Branch now appears as Registered.