KB "Wrong firewall policy sequence will cause high CPU during policy add/modify"
Fortinet recently published (according to my RSS feed, 1st October) "Wrong firewall policy sequence will cause high CPU during policy add/modify" implying that for optimum performance during business-as-usual provisioning of firewall policies, most popular rules should be placed topmost in Policy sequence and in fact it is a "wrong firewall policy sequence" methodology to do it otherwise.
The issue I have is that Policy sequence dictates order of matching to traffic, and a policy that matches most traffic is most likely to be most general and hence be at the bottom. In fact, as per FortiOS Handbook for FortiOS 5.2.4, section 'Policy order', "... make sure that the more specific or specialized a policy is, the closer to the beginning of the sequence ..."
I feel that publication an KnowledgeBase like this is evidence that Fortigate's Policy-related algorithms are insufficiently engineered. Or, perhaps, I'm missing logic that justifies it?
