Technical Tip: FortiProxy - Packets pass though via a Transparent Policy with the action 'DENY' and 'set log-http-transaction enable'
| Description | This article describes when a transparent proxy policy with the action "DENY" may allow packets to be transmitted. |
| Scope | FortiProxy with transparent proxy policy earlier than v7.0.21, v7.2.14, v7.4.9, and v7.6.3. |
| Solution | The feature called 'Log HTTP Transaction' is used to log HTTP transactions. When this feature is enabled in the Transparent Policy where the action 'DENY', the policy lets packets pass through until it sees 'HTTP Transactions'.
CLI Configurations:
config firewall policy
Forward Traffic Log:
This has been identified as a bug and will be fixed in the upcoming v7.0.21, v7.2.14, v7.4.9, and v7.6.3.
Workaround: Disable 'Log HTTP Transaction' in the policy with the action 'DENY'.
config firewall policy
Related article: Troubleshooting Tip: No logs are appearing in HTTP Transaction Log |

