Skip to main content
jasonhong
Staff & Editor
Staff & Editor
December 4, 2024

Technical Tip: How to troubleshoot when FortiManager tries to unset fwpolicy-implicit-log

  • December 4, 2024
  • 0 replies
  • 379 views
Description

This article describes how to troubleshoot when FortiManager tries to unset fwpolicy-implicit-log.

Scope FortiManager.
Solution
  1. When performing a policy package installation, the user may come across the scenario where FortiManager is trying to unset fwpolicy-implicit-log within the installation preview although the fwpolicy-implicit-log is already set to enabled in the device database.

 

config log setting

    unset fwpolicy-implicit-log enable

end

 

devdb.png

 

  1. The user can verify the implicit log configuration of the firewall policy within the policy package. If the implicit log is set to 'Disable' or 'No Log' within the firewall policy, FortiManager will try to disable the implicit log setting during the policy package installation.
  2. To ensure FortiManager does not disable the implicit log setting during policy package installation, ensure 'Log IPv4/6 Violation Traffic' is enabled in the firewall policy within the policy package.

 

implicitlog.png