Created on 12-26-2022 11:35 PM Edited on 01-28-2024 09:03 PM By Anthony_E
Description | This article describes that from v6.2, the IP address might be part of different ISDB objects. |
Scope | FortiGate v6.2 and above, |
Solution |
The traffic is matched based on the 3-tuple (protocol, port, IP). This also introduces the 'singularity' value that means the highest weight, i.e. which ISDB object will be matched based on the 3-tuple.
chameleon-kvm14 # diagnose internet-service info root 6 443 40.101.76.130
chameleon-kvm14 # config firewall internet-service 327880 chameleon-kvm14 (327880) # get
chameleon-kvm14 # config firewall internet-service 327791 chameleon-kvm14 (327791) # get
diagnose sys session filter src 10.100.13.195 session info: proto=6 proto_state=01 duration=1 expire=3598 timeout=3600 flags=00000000 socktype=0 sockport=0 av_idx=0 use=3 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.