FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
arahman
Staff
Staff
Article Id 387403
Description This article describes the steps to check unused policies in FortiGate.
Scope FortiGate. 
Solution

In some scenarios, it is necessary to check the unused policies in FortiGate to cleanup or for security reasons. Unused policies are policies without any traffic hits. To view them, navigate Policy & Object -> Firewall Policy and select Security Rating Issues in the bottom-left corner.

 

kb 17.1.PNG

 

Select the Security Rating Issues option in order to select unused policies in the FortiGate. 

 

kb 17.2.PNG

 

Select unused policies to highlight the policies. Navigate with the right and left buttons that appear. Additionally, the last time the policy was checked for the usage will be shown. 

 

Check the exact time the policy was last used by selecting 'edit' on a specific policy. For example:

 

kb 17.3.PNG

 

The security Rating Issues also show other options like the following:

  • Policy Inspection Mode shows the policies that have incorrectly used a inspection mode for security profiles.
  • Audit Log Settings shows the policies that have UTM logging selected instead of All logging.

 

It isalso possible to filter on policies with 0 bytes to see this info, in case there is no Security Rating entitlement:

 

 
0bytes.PNG

In v7.6, the Unused policy option is renamed to 'Not Recently Used Policies', as shown below:

 

kb 17.4.PNG

 

Note:

The statistics will reset after the FortiGate has been rebooted.