Skip to main content
jammac
Explorer II
March 14, 2025
Question

Policy search of IP always returns "all"

  • March 14, 2025
  • 3 replies
  • 1877 views

Using the search bar to search for an IP address at the top of the firewall policy screen in FOS 7.4+ always includes as a result any rule containing the "all" object.

 

How do I turn this behavior off? While it's logical, for me it's uninteresting (unless I would specifically want it that way).

 

This worked just fine in < 7.4, i.e. a search gave all policy rules containing a subnet or group or anything that contains what I am looking for, but not "all".

3 replies

ebrlima
Staff
Staff
March 14, 2025

Hello @jammac 

 

 

I see that the behavior did in fact changed. I'll be looking internally to see if it's the new expected behavior and if there any way to change it.

radonba2
New Member
March 15, 2025

Yes, this I am aware of. For the time being I feel safe and confident that that's not going to happen. I live in Sweden and am not in any way suppressed by my government, I'm not involved in any illegal activity, no file-sharing, not a journalist and not an activist. If however things were to change politically, or I were to start file-sharing again, I would definitely get a VPN and protect my IP.

Stephen_G
Staff & Editor
Staff & Editor
March 16, 2025

Hello radonba2,

 

Thank you for posting. Your post is a little off topic, can you please look for a relevant board to post to, or create a new thread. 

 

Thanks,

Stephen_G - Fortinet Community Team
ebrlima
Staff
Staff
March 19, 2025

Hello @jammac 

 

I've checked with the dev team and this is the new behavior. It is not an issue and also it is not configurable.

jammac
jammacAuthor
Explorer II
March 19, 2025

Ok thanks for getting back, much appreciated.

Well for me it is an issue.

I can search by object instead, which will not include "all", but which also will not include any group or subnet the object is a member of.

 

So it's not even more complicated to get the old behavior, but impossible.

Or is there a workaround that I maybe haven't though of yet to get the result of the old behavior without too much hassle?
Short of exporting the results and running them through some filter manually...?

 

(If there is a new behavior, it should be justifiable and configurable.)