Skip to main content
mle2802
Staff
Staff
December 3, 2025

Troubleshooting Tip: How to enable 'Log IPv4 Violation Traffic' under an Implicit deny policy when Security Fabric is configured

  • December 3, 2025
  • 0 replies
  • 645 views
Description This article describes how to enable 'Log IPv4 Violation Traffic' under an Implicit deny policy when Security Fabric is configured. This applies to both root and downstream FortiGates.
Scope FortiGate.
Solution When trying to enable log option for an Implicit deny policy under Policy & Objects -> Firewall Policy, the option is grayed out and cannot be enabled.

Screenshot 2025-12-02 152319.png
The button will be grayed out when the Security Fabric is configured. To enable the 'Log IPv4 Violation Traffic' option on both the root and downstream FortiGates, use the following CLI commands:

config log setting

    set fwpolicy-implicit-log enable

end


Afterwards, the option 'Log IPv4 Violation Traffic' will show as enabled.

Screenshot 2025-12-03 133553.png
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.