Created on
‎09-25-2024
12:42 AM
Edited on
‎07-21-2025
01:03 AM
By
Anthony_E
Description | This article describes how to troubleshoot issues where traffic does not match any policy although the policy is already created. |
Scope | FortiGate. |
Solution |
In this example, a policy has been created to allow all traffic from port 2 to port 1 (internet), however, traffic does not match the policy. A ping test is done from the user (10.xx.xx.59) to 8.8.8.8 failed due to no policy matching.
Debug flow showing below:
id=65308 trace_id=2 func=__iprope_check_one_policy line=2256 msg="gnum-100004 policy-XXX is not active" ... ...
To troubleshoot this issue, the following can be done:
get router info routing-table details 10.xx.xx.59 Routing table for VRF=0
get router info routing-table details 8.8.8.8 Routing table for VRF=0
config firewall policy
Verify that all named object is configured correctly. This can be done by hovering on each object on the policy.
The service ALL has been changed to a specific port which causes traffic not to match the policy.
Ensure that the proper name is being used to represent its object. In this example, the service is named 'ALL', but it is only configured for some specific ports.
In the following example, Saturday and Sunday are missing. The time is only between 9:00 AM to 12:00 PM.
This could be confusing when configuring the policies and troubleshooting policy-related issues. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.