Skip to main content
Hersy
New Member
January 15, 2020
Question

log action definition

  • January 15, 2020
  • 2 replies
  • 12438 views

Running version 6.7 and i need to find a definition of the actions i see in my logs. Example below

 

action = pass vs action = accept.

 

I would like to see a definition that says some thing like the close action means the connection was closed by the client. Something like that.

    2 replies

    darwin_FTNT
    Staff
    Staff
    January 15, 2020

    the action field in traffic log has the following possible values:

     

    deny accept start dns ip-conn close timeout client-rst server-rst

    For regular firewall policy, wad firewall policy or sniffer policy, if it doesn't matched the rules, then action is immediately deny. Otherwise, it could have the rest of the values.

     

    For ngfw firewall policy, it just matched the policy action, which is either accept or deny.

     

    The action is for policy only, utm action (if any utm/security profile is attached to the firewall policy) could be different from the policy action.

    emnoc
    New Member
    January 15, 2020

    I wrote this up a while back for the fields, it might come handy

     

    http://socpuppet.blogspot.com/2016/08/using-execute-log-filters-to-monitor.html

     

    I Believe nothing new has been added, but use the "execute log filter field" Action for tlog is  accept or deny

     

    Ken Felix

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!