Skip to main content
duenlim
Staff
Staff
October 27, 2025

Technical Tip: The hit count show '0' when traffic match the implicit deny in Explicit Proxy Service

  • October 27, 2025
  • 0 replies
  • 125 views
Description

This article describes that the hit count does not increase when the packet hits the implicit deny rule in the  Explicit Proxy Service.

 

DenyLog_HitCount.jpg

Scope FortiProxy v7.2, v7.4 ad v7.6.
Solution

The hit count value can be seen via CLI commands as follows: 

 

diagnose wad worker policy list | grep "implicit proxy deny" -A5

 

implicit proxy deny policy, VDOM:root p_id:0
Client In: 20854428, Out:0 server In: 0, Out: 0
Kernel: 0
active_sessions: 3, n_hits: 43143    <----- The hit count value is 43143.
first access: Fri Aug 29 12:02:02 2025
last access: Sat Oct 25 10:50:51 2025