Skip to main content
Robert_Cerny
New Member
October 31, 2016
Question

Firewall LEARN rule

  • October 31, 2016
  • 1 reply
  • 8157 views

Hi folks,

does anybody know how much time/traffic needs LEARN rule to actually show anything in the Log? I have it set up for 5 days and 30GB of traffic went through but still don't see any result.

1 reply

emnoc
New Member
October 31, 2016

Qs:

 

What do you mean by learn rule?  have  you conduct any "diag debug flow" commands to validate that traffic is actually hit that rule that you suspect?

 

 

Robert_Cerny
New Member
October 31, 2016

LEARN rule is the new thing in FortiOS 5.4.1. You have another fw rule to ACCEPT and DENY named LEARN, which checks packets and according to docs after some time shows its results in Log & Report pane.

 

[link]https://www.youtube.com/watch?v=LI3bW2eO-ck[/link]

MikePruett
New Member
October 31, 2016

Emnoc is right. Can you verify that traffic is truly hitting this policy? Chances are it needs to be higher up on the policy set as an existing policy may be letting the traffic traverse before it gets down to the learn rule you created.