Description | This article describes how to troubleshoot traffic denied by an implicit policy when threat ID 131072 appears on the logs. |
Scope | FortiGate. |
Solution |
The traffic is being denied by policy 0, particularly if it is hitting with LAN to WAN Policy. Verify with the Forward traffic logs if threat ID 131072' is high 30; verify any IP pool configured on the Firewall Policy.
On the Firewall Policy, verify any Dynamic SNAT configured and follow the action plan below:
Once the IP Pool configuration is changed or set with the correct NAT overload range, the traffic will pass through via the same Policy ID. In case of multiple outgoing interfaces are referred in firewall policy(SD-WAN) use associate interface under IPPOOL configuration. So it uses the SNAT from associated interface POOL only.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.