5.2.2 bug causes ALL service group to be ignored
Just thought I'd post this here for others who have the same issue in future. According to Fortinet support there is a bug in firmware 5.2.2 that causes the "ALL" service group to be ignored, so any policy rules that use it will be ignored. It is fixed in 5.2.3, and in the meantime use "ALL_UDP, ALL_TCP & ALL_ICMP" instead of "ALL".
We upgraded a 100D on Saturday from 5.0.2 to 5.2.2 (following the correct upgrade process) on Saturday and today noticed some traffic being blocked. The GUI logs just showed "deny" with a PolicyID of 0 (no such policy ID visible). From the CLI a debug showed "Denied by forward policy check (policy 0)" for any traffic that used the ALL service group.
