Description | This article describes how to check whether the firewall policy is oversized. |
Scope | FortiGate. |
Solution |
A policy can potentially become oversized when modifying a variety of objects. It can cause the policy to malfunction when it is oversized.
Hence, the following command can be used to check whether a firewall policy is oversized:
diagnose firewall iprope show 00100004 X
Note: Replace 'X' with policy ID. The ID can be checked from the GUI. For more information: Technical Tip: How to find policy ID
Here is the sample output from the debug command above:
Tiara-kvm05 # diagnose firewall iprope show 00100004 1 first est:2023-07-25 14:26:06 last est:2024-12-02 09:35:26
From the output above, check 'flag' output:
|