Skip to content

5651 LOGGING

FortiGate Law 5651 logging: signed, audit-ready records.

Access records from your FortiGate devices are collected over syslog, every line is sealed and the daily archive is signed with a qualified Kamu SM timestamp. Meet the record-keeping duty of Turkish Law No. 5651 in the cloud or on your own server.

Signed log archive screen: daily per-device archives with record counts and RFC 3161 timestamp status
Archives and timestamps · Customer data replaced with sample values.

Key Capabilities

01
Qualified timestamp

The daily archive is signed with an RFC 3161 timestamp obtained from the Kamu SM (TÜBİTAK BİLGEM) timestamp authority, proving the record existed on that date.

02
Hash chain

Every record line is sealed with an HMAC and daily archives are chained together. Changing a single line breaks the chain and shows up in verification.

03
Permanent archive

Signed daily archives are never deleted; they remain accessible and downloadable throughout the statutory retention period.

04
Audit-ready reports

When an official request arrives, records for the relevant period are searched and a compliance report is exported as PDF.

How do you set up Law 5651 logging on FortiGate?

No extra hardware. Once your device is registered in the panel, the log flow starts in four steps.

Add the device

Your FortiGate is registered over its existing internet connection via REST API or SSH.

Enable syslog forwarding

The panel generates the syslog configuration for your device; FortiGate starts sending records to the collector.

Records are sealed

Every incoming log line is sealed with an HMAC; daily archives are chained to one another.

The archive is signed

The daily archive is signed with a qualified RFC 3161 Kamu SM timestamp and kept without deletion.

Sample FortiGate syslog configuration
config log syslogd setting
    set status enable
    set server "<collector-address>"
    set port 5514
    set mode udp
end

Sample only. The panel generates the full configuration for you, including the collector address and settings suited to your device.

Which FortiGate records are collected under Law 5651?

  • Traffic logs: source and destination IP, port, session start and end time
  • Local traffic, event and anomaly logs
  • Hotspot sessions: SMS-verified user, device and time
  • A Kamu SM timestamp and integrity digest for each daily archive

What does Law No. 5651 require?

Mass-use internet providers must keep access records, preserve their accuracy and integrity, retain them for the statutory period and produce them on request. Records must be signed with a timestamp.

Law 5651 Guide

Compliance checklist

  • Collecting access records from the device
  • Sealing every record with a hash
  • Signing the daily archive with a qualified timestamp
  • Being able to verify archive integrity at any time
  • Producing reports on official request

FortiGate Law 5651 logging FAQ

No. In the cloud setup, records are collected and signed on our servers in Türkiye. If you prefer data not to leave your premises, the platform is installed on your own server and the licence is verified from a signed file with no internet connection required.
Models running current FortiOS with REST API v2 or SSH access are supported. Records are sent with FortiGate’s built-in syslog feature, so no extra software is installed on the device.
Signed daily archives are never deleted; they remain accessible and downloadable for the legal retention period. The last month of records is searchable directly in the panel.
A timestamp proves to a third party that a record existed on that date and has not been changed since. The daily archive is signed with an RFC 3161 timestamp from the Kamu SM (TÜBİTAK BİLGEM) timestamp server.
Yes. Every SMS-verified guest session is recorded with identity, device and time information and written to the signed daily archive.

How many devices do you have? Let us work out the rest.

Fill in the two-minute wizard; we will send a tailored quote within one business day.