Skip to main content
vvserpent
Explorer
June 10, 2016
Question

Firewall Action

  • June 10, 2016
  • 13 replies
  • 47943 views

Hi,

 

The security auditor came to our office to check the Firewall Policies.  The guy suggests to configure the Firewall Access Rule to "DROP" the unwanted traffic instead of "DENY". 

 

When setup Firewall Access Rule, I can select "ACCEPT" or "DENY" only.

 

Is it possible to configure the Fortinet Firewall do "DROP" instead of "DENY" ? 

 

Regards,

 

    13 replies

    ede_pfau
    SuperUser
    SuperUser
    June 10, 2016

    As far as I know packets are dropped silently when they match a DENY policy. If the auditor envisions that denied traffic always terminated by a RST handshake, and dropped traffic is just discarded without any answer, then FOS uses implicit DROP policies.

     

    This is quite easily confirmed by sniffing the destination interface.

    omega
    New Member
    June 10, 2016

    Like so many things this seems possible via CLI.

     

    Look into:

    http://kb.fortinet.com/kb....do?externalID=FD36465

    ede_pfau
    SuperUser
    SuperUser
    June 10, 2016

    Nice find!

    In the article they state "TCP - will send TCP Reset like before". So by default TCP is denied by sending an RST (not silently dropped as I presumed.

    The rest of the article describes how to make denials more verbose by invoking an ICMP message - just the opposite of what OP is looking for.

    New Member
    June 4, 2026

    Sorry to necro bump this but to me there are times when you want a real DENY or DISCARD

    and for Fortinet to decide that really DENY is just DISCARD means the action within the Policy creation wizard is misnamed and really it should be named to match what it does!

     

    There is a functional difference between DENY & DISCARD 

    We all know this.

     

    I’ve been dealing with firewalls of different types for decades and these 2 actions are never mixed and are always available.

    DENY is not and never will be DISCARD

    Both actions should be available regardless of use case or defaults.

    It’s the sane thing to do

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!