Skip to main content
itmdadmin
New Member
July 4, 2024
Question

Traffic match with wrong Schedule

  • July 4, 2024
  • 19 replies
  • 5994 views

Foritgate FW version : 7.4.4

I have created two proxy policy with different schedule, office hour and non office hour.

and i notice that the traffic is matched with non office hour schedule and policy when I access internet in office hour. 

anyone have experience this issue ? 

 

Observed Update on 8/July/2024:

Traffic between 4PM to 3 AM will go to office hour policy with schedule 8AM-7PM

Traffic between 3AM to 4 PM will go to non office hour policy  with schedule 7PM-8AM  

 

 

Office_Hour.pngNon_office_hour.pngTraffic_log.png

 

 

19 replies

itmdadmin
itmdadminAuthor
New Member
July 4, 2024

sry are you replied a wrong post... 

hbac
Staff
Staff
July 4, 2024

Hi @itmdadmin,

 

I can't reproduce this issue in my lab. Please check FortiGate timezone and make sure it is correct. You can also collect debug flow to see if it really matches that policy. https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

 

Regards, 

itmdadmin
itmdadminAuthor
New Member
July 8, 2024
  1. Timezone is correct and I have worked with a foritgate engineer to troubleshoot it but still not solved and the case is under researching....
hbac
Staff
Staff
July 8, 2024

Hi @itmdadmin,

 

Does it also happen to regular firewall policy or just proxy policy?

 

Regards,

HarshChavda
Staff
Staff
July 5, 2024

Hello,

 

Can you verify source and destination in policy look up and Check to see there are no other firewall rules that supersede this rule.  Remember that firewall rules are processed from top-to-bottom.

itmdadmin
itmdadminAuthor
New Member
July 8, 2024

there is no other policy that will supersede those two rules

sw2090
SuperUser
SuperUser
July 8, 2024

what I see is that your one schedule's ending time is exactly the start time of the other and vice versa.

Probably this might result in sessions being created with wrong policy because both are active for that minute and then the first will  match?

itmdadmin
itmdadminAuthor
New Member
July 8, 2024

we had try setting the start time and end time with 1 min different but still the same result. 

smaruvala
Staff
Staff
July 8, 2024

Hi,

 

- Do you see the issue all the time or only for a specific period of time every day?

- Is the "fast-policy-match" configuration enabled in the Firewall? 

 

Regards,

Shiva

itmdadmin
itmdadminAuthor
New Member
July 9, 2024

It happen all the time.

The "fast-policy-match" is not configurated, is it default enable ? shall i disable it ?

smaruvala
Staff
Staff
July 9, 2024

Hi,

 

- When was the Policy created? I can see the issue started from 8th of June. Was the Policy created on 7th of June?

- In the screenshot we can see the schedule status is showing as inactive. But if you edit the policy and go into the policy then check the status of schedule, does it show inactive or active?

- I think I am able to reproduce the issue in the lab. I did not face the issue yesterday. But today I am seeing the issue. So I am assuming it was matching office-hours proxy policy first. Then during non-office hours it was matching the non-office policy and it has not changed back to office hours policy.

- I would suggest you to open a support case. Replication should be possible in version 7.4.4 but I think we need to give one day time. If you have already opened the case let me know the case number.

 

Regards,

Shiva

ede_pfau
SuperUser
SuperUser
July 9, 2024

I think it is related to session lifetime. When the correct schedule is matched, a session is allowed to be established. Then the schedule expires, but the session is not re-evaluated ('dirty').

Isn't there an option to force that lookup?

 

There is an option which governs the behavior of active sessions vs. schedule expiration:

config firewall policy

edit <nn>

set schedule-timeout enable

 

If enabled, sessions will be terminated on schedule expiry. If disabled, active sessions are allowed to continue while new sessions will be prevented. Disabled is the default.

I'd give it a try.

itmdadmin
itmdadminAuthor
New Member
July 9, 2024

After some test, its seems that the scheduler is using the GMT+0 as the measure time instead of my local time GMT+8

SRaudi
Visitor III
September 7, 2024

Yes! Same here, today i updated from 7.4.2 to 7.4.4 and the schedules stopped working.

 

During research i found this post and moving the schedule 2 hours in the past is working here also.

 

Thanks for the hint!

Debbie_FTNT
Staff & Editor
Staff & Editor
September 10, 2024

Hey guys,

 

thanks for the info and detective work you've already done!

I had a look through the internal bug database, but didn't find anything for 7.4 and scheduler issues; I did find something for 7.2 that necessitated a fix for the scheduler, so perhaps something went slightly wrong? I've posted an update to the engineering team regarding this.

 

Cheers,

Debbie

SRaudi
Visitor III
September 10, 2024

Hi @Debbie_FTNT,

 

i noticed also that this problem is only when using schedules in the web proxy config. When using schedules for switching on/off WLAN SSID's the schedules are working normal.

Debbie_FTNT
Staff & Editor
Staff & Editor
September 10, 2024

Thanks for the clarification, SRaudi :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!