Question
Implicitly denied traffic not logged while using a VIP with external IP matching interface
Can someone explain to me why using a VIP with an external IP that matches the interface of the firewall causes implicit deny traffic to no longer be logged? I have implicit deny logging enabled but for whatever reason when I use a VIP with port forwarding it seems to no longer log the denied traffic that had a destination IP of the firewall interface. I'm running FortiOS 5.0.7. Do I need to make an additional policy blocking all ports to the VIP an logging it?
