Fortigate policy-based mode possible application shift issues.
Hello All,
Interesting thing this Policy-Based NGFW mode compared to the profile-based default mode.
NGFW policy | FortiGate / FortiOS 7.6.3 | Fortinet Document Library
I played a little and when for example you have rule that blocks ssl before a rule that allows Web Browser app then it will never reach the second rule as the app shifts after some time like I have seen on other firewall vendors that policy-based modes for app control.
There should be an article how to see the application shift for a session for people using this mode, also a "diagnose debug" command as well for app control showing all the identifications for a session traffic like SSL > WEB Browser > SAAS app etc. As of now I think the default profile mode is better.

