Skip to main content
rmetzger
Staff
Staff
April 10, 2009

Technical Tip: Troubleshoot and verify if traffic is hitting a Firewall Policy

  • April 10, 2009
  • 0 replies
  • 12559 views

Description

 

This article describes when there are many Firewall Policies for a specific interface pair, an easy way to see if a policy is actually hit by some traffic is to add the counter field in the GUI.


Scope


FortiGate, FortiOS.

Solution

 

  1. From the GUI, navigate to  Policy & Objects -> Firewall Policy.
  2. Select the 'Configure Table' option as shown in the screenshot below:

 

232323.png

 

  1. Select 'Hit Count' as well as 'Bytesand then Apply:
     

    444444.png

     

     
  2. Now verify that some packets hit this Policy will show the number of policy hits and Bytes as shown in the screenshot below:
     
 
5555555.png
 
For real-time troubleshooting for current traffic, validate the sessions table and policy match: Technical Tip: How to know wich policy ID is used in FortiGate session table
 

Note:

For accelerated traffic (ex. NP2 ports), only the start of the session packet will be counted, and this counter does therefore not reflect the real traffic count. For non-accelerated traffic, all packets will be counted.

Related articles:

Technical Note : Configuring a Firewall Policy which is valid only at certain days or hours by using a schedule

Technical Tip: Information about traffic log counters for NP2 or NP4 offloaded sessions

Technical Tip: How to clear Firewall Policy counters