FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rmetzger
Staff
Staff
Article Id 197261
Description
When there are many Firewall Policies for a specific interface pair, an easy way to see if a policy is actually hit by some traffic is to add the counter field in the GUI.
Scope
All FortiGates

Solution

1.  From the GUI, select Firewall, Policy   Then [ Column Settings].


rmetzger_counters_fwp1.JPG
2. Add the Count field.

rmetzger_counters_fwp2.JPG



3. Now verify that some packets hit this Policy will be counted (in KB)

Note : For accelerated traffic (ex. NP2 ports), only the start of session packet will be counted, and this counter does therefore not reflect the real traffic count. For non-accelerated traffic, all packets will be counted.

rmetzger_counters_fwp3.JPG

Related Articles

Technical Note : Configuring a Firewall Policy which is valid only at certain days or hours by using...

Technical Tip: Information about traffic log counters for NP2 or NP4 offloaded sessions

Technical Tip: How to clear Firewall Policy counters

Contributors