| Description | This article describes an issue where some Firewall policies show a zero hit count, but there is a non-zero Byte count. |
| Scope | FortiGate, FortiProxy. |
| Solution |
When visiting Firewall or Proxy policies, it is possible to observe zero hit count and non-zero Byte count as below.
The packet counter is mostly stuck. To rectify the issue, below steps can be actioned.
Make sure there are no active sessions on the policy by running the commands below:
diagnose sys session filter policy 3000 total session: 0
If there are any active sessions, clear them using the command below.
Note: This will affect sessions of users who are using this policy.
Verify the current status of the packet count by using the command below. The example below is for a policy where there is current traffic with a hit count that is non-zero.
diagnose firewall iprope show 100004 2
The example below is for a policy where there is no current traffic, with a hit count is zero, but the Byte count shows a non-zero value due to stuck packets.
diagnose firewall iprope show 100004 3000
Clear the packet counts:
diagnose firewall iprope clear 100004 3000 diagnose firewall iprope show 100004 3000 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.