Question
is it possible to better debug / determine policy choice?
had an issue recently where the choice of a policy made totally no sense for certain traffic.
i use diagnose debug flow and see pretty much no other useful information the the choice of policy ID.
is there something else i can do? it would be great if there is some extra option to actually list why the fortigate feels that traffic matches a certain policy.