Description
This article provides a sample of firewall policy lookups.
Scope
FortiGate.
Solution
Policy lookups.
The Policy Lookup tool has the following requirements:
Sample Configuration.
This example uses the TCP protocol to show how policy lookup works:
Note:
From the 7.4 version, the option is changed to 'policy match'.
Alternatively, use the following command to trace specific traffic on which firewall policy it will be matching:
diag firewall iprope lookup <src_ip> <src_port> <dst_ip> <dst_port> <protocol> <Source interface>
Example:
diag firewall iprope lookup 10.187.1.100 12345 8.8.8.8 53 udp port2
<src [10.187.1.100-12345] dst [8.8.8.8-53] proto udp dev port2> matches policy id: 0
diag firewall iprope lookup 10.187.1.100 12345 8.8.8.8 53 tcp port2
<src [10.187.1.100-12345] dst [8.8.8.8-53] proto tcp dev port2> matches policy id: 2
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.