| Description | This article describes how to check the policies and the ordering from the CLI. |
| Scope | Any supported version of FortiGate. |
| Solution |
Below commands can be used to check the policy order and policy configuration from CLI.
get firewall policy
This command will list all the policy ID in the top to bottom order:
DCFW_Pri # get firewall policy
This will be useful to understand the ordering of the policies, troubleshoot traffic matching wrong policy, and reorder the policies.
show firewall policy
This command will show the configuration of the policies in the top to bottom order. If there are large numbers of policies, then it is possible to specify the policy ID to display the output:
show firewall policy <ID>
DCFW_Pri # show firewall policy 3 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.