Skip to main content
topcu
Explorer
July 31, 2020
Question

Report about policy hits: srcip+dstip+proto+port (FAZ/FMG)

  • July 31, 2020
  • 0 replies
  • 2210 views

Hello all, because I want to optimize some roughly builded policies on our firewalls, I need an overview about actual communications, that are passing through some policies in a 3 month history review. I thought about to use the report feature of the FortiAnalyzer (2000E, v5.6), but didn't find an proper template. I would like to see all sessions cumulated in a socket manner per policy ID, that means, source-ip + destination-ip + protocol + port, and optional the amount of such individual sessions.

Is there such a template available, or can anyone share such a template? Or do you have another idea, how to evaluate those informations? Fortimanager 6.2.5 is also available.

Many thanks in advance / best regards, Hakan

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.