FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
wdeloraine_FTNT
Article Id 388678
Description This article describes how packets are processed when they match a flow rule.
Scope FortiGate-6000F, 7000E and 7000F series.
Solution

On chassis-based FortiGate, a packet eligible for load-balancing goes through to the FPM in this order:

  • Front port.
  • ISF.
  • DP (distribution processor).
  • FPM (via the ISF).

 

without-flowrule.png

 

The packet goes straight to the FPM when the corresponding traffic pattern is caught by a flow rule.

 

with-flowrule.png

 

This behavior could be useful during a troubleshooting session when a load balancing problem is suspected.

Once the flow rule matches the problematic traffic, the chassis will act as a regular FortiGate. It means that no more load-balancing features will be involved.

 

Related document:

Load balancing and flow rules