I don't understand the actions for the type log: LOG_ID_TRAFFIC_END_FORWARD
According to documentation provide for Fortigate exist multiple actions as:
The status of the session: deny - Session was denied
accept - Allowed Forward session
start - Session starts (log message was created when the session was created)
dns - DNS query return error
ip-conn - Failed connection attempts
close - Local-traffic session allowed
timeout - Allowed session was timeout
client-rst - Session reset by client
server-rst - Session reset by server
I receive a lot of connections with the action "close" and I have a number of doubts:
If an incoming traffic has had the action "close", is it a successful connection or has nothing to do with it?
That same incoming connection must have a "Firewall Permit" event before or it is not necessary?
