Skip to main content
Borys_DE
Explorer II
October 23, 2025
Question

Some problem with local-in policy when using ISDB as a source

  • October 23, 2025
  • 1 reply
  • 449 views

Hello everyone, 

I created a local-in policy as described in this example: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Local-in-policy-using-ISDB-as-a-source-address/ta-p/323085

Overall, the policy works, but for some reason, some IP addresses contained in the ISDB, and these ISDBs are listed as sources in this policy, are not blocked.

What could be the reason?

1 reply

AEK
SuperUser
SuperUser
October 23, 2025

Hi Borys

At this point we need to see if the issue is in your ISDB or in the local-in policy.

So please use the same ISDB in a regular firewall policy and see the related IP addresses are blocked or not.

AEK
Borys_DE
Borys_DEAuthor
Explorer II
October 23, 2025

Hi AEK, 

I see in the list of addresses blocked by local policy several addresses that are contained in the problematic database. By the way, over the last day I discovered two unblocked addresses, which were contained in two different databases.
This means that I need to check at least two ISDBs. It’s not entirely clear to me how to do this, if I already see that the addresses contained in the ISDB are blocked, although not all

funkylicious
SuperUser
SuperUser
October 23, 2025

hi,

you can check to which ISDB they belong to, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Common-Internet-Service-Database-Feature-admin/ta-p/192971 

 

e.g. diagnose internet-service match root IP MASK

"jack of all trades, master of none"