Skip to main content
mlourenco
New Member
October 3, 2016
Solved

Forward Traffic and Local Traffic in Log & Report section

  • October 3, 2016
  • 1 reply
  • 61245 views

Hello,

 

I have a fortigate 100D.

 

Can you tell me the difference between forward traffic and local traffic in Log & Report section?

 

 

 

 

 

 

    Best answer by Debbie_FTNT

    Hi Mlourenco!

     

    Local traffic is traffic destined for any IP on the FortiGate itself -> management IPs, VIPs, secondary IPs etc.

    Any traffic NOT destined for an IP on the FortiGate is considered forward traffic.

     

    Regarding local traffic being forwarded:

    This can happen in cases of VIP and similar setups. We have traffic destined for an IP associated with the FortiGate itself (the external IP of the VIP), and the FortiGate will do DNAT to the internal IP and then forward the traffic to the internal IP. It will still be considered local traffic, because the initial traffic (prior to DNAT) is addressed to the FortiGate directly.

     

    Does this clear up the confusion?

    1 reply

    rwdorman
    New Member
    October 4, 2016

    Local traffic is traffic directed to the Fortigate itself on one of its management interfaces.  Forward traffic is that traffic permitted or denied by a firewall policy. (and "forwarded" to its destination)

    mlourenco
    mlourencoAuthor
    New Member
    January 30, 2017

    But, local traffic can be forwarded also? What's the diference between both?

    Debbie_FTNT
    Staff & Editor
    Staff & Editor
    February 3, 2017

    Hi Mlourenco!

     

    Local traffic is traffic destined for any IP on the FortiGate itself -> management IPs, VIPs, secondary IPs etc.

    Any traffic NOT destined for an IP on the FortiGate is considered forward traffic.

     

    Regarding local traffic being forwarded:

    This can happen in cases of VIP and similar setups. We have traffic destined for an IP associated with the FortiGate itself (the external IP of the VIP), and the FortiGate will do DNAT to the internal IP and then forward the traffic to the internal IP. It will still be considered local traffic, because the initial traffic (prior to DNAT) is addressed to the FortiGate directly.

     

    Does this clear up the confusion?