Match-vip clarification for deny rules
I'm trying to clarify my understanding of match-vip in firewall policies. This is for 5.4.5.
Per http://docs.fortinet.com/d/fortigate-fortios-5.4.4-cli-reference, page 92, you need to set match-vip on any DENY rule to allow that rule to actualy match DNATed packets. This was discussed quite a bit in thread: https://forum.fortinet.com/tm.aspx?m=112129.
The documentation also states that the default implicit deny rule *may* not actually match in these cases and the packet will be silently dropped.
Questions:
[ol]
Thanks in advance for any clarification of this.
