Skip to main content
rafiki
New Member
March 22, 2019
Solved

New policy install drops established connections traffic

  • March 22, 2019
  • 1 reply
  • 2943 views

Fortigate 1500D

Firmwarev6.0.4 build0231 (GA)

Mode NAT (Flow-based)System

 

Hello,

When I install a new policy, the firewall drops the estabilished connections packets affected by the new rule.

E.g. If I have a nfs connection, after policy applying, I have to restart it. It happens the same with database connections.

Is there any workaround to avoid restart systems?

 

Thank you

Rafa

    Best answer by ede_pfau

    I'd say that is application dependent. Of course, changing the policy will make the FGT end all sessions running across it. With HTTP, a new session buildup will only take milliseconds. With other protocols and/or applications it might be different.

     

    So the workaround is to not change the policy too often. Ending sessions allowed in it's previous incarnation and re-evaluation them is a principle, not a flaw.

    1 reply

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    March 22, 2019

    I'd say that is application dependent. Of course, changing the policy will make the FGT end all sessions running across it. With HTTP, a new session buildup will only take milliseconds. With other protocols and/or applications it might be different.

     

    So the workaround is to not change the policy too often. Ending sessions allowed in it's previous incarnation and re-evaluation them is a principle, not a flaw.