Skip to main content
JardaTesar
New Member
August 15, 2018
Question

Sessions Blocked in FortiView

  • August 15, 2018
  • 1 reply
  • 5611 views

Hello,

I set up some policies for VIPs to allow access to services on my internal server, and now monitoring the traffic in FortiView I can see a lot of addresses in Traffic from WAN - Sources that Session is Blocked. Does this mean that this connection was really blocked, or is it just session that went through but is now closed? If it is really a blocked session, where can I find what is blocking it? I was digging around but couldn't find any more information. I even tried to disable all security profiles, but the sessions are still appearing as blocked, but the Policy seems to be set up right to allow all traffic on those ports. 

Thank you.

1 reply

gagandeeps
Staff
Staff
September 22, 2023

Go to Dashboard-> Fortiview session -> enter destination IP. Right-click on the IP address or hostname related to that and drill down. Once you see different sessions listed you can click on settings to customize the table to be viewed and select action. you will be able to see multiple reasons for deny, for eg: TCP reset from server, session closed, timeouts etc.