This article describes possible reasons why sources may not be seen for a VIP under Fortiview Sources, when protecting a website/service with the FortiGate.
In the following example, a service running on a Webserver behind the FortiGate is accessed. It can be accessed via the internet from a device with Public IP 20.73.17.183, but FortiView sources shows nothing matching this IP:
FortiOS.
The Flow for this traffic is as follows:
Client -> Internet -> FortiGate WAN -> Webserver.
Results are not obtainable because the WAN1 interface of the FortiGate has the role 'WAN' selected:
By design, results will only be seen under FortiView Sources if the source interface is set to 'LAN' or 'Undefined'.
Changing the Wan1 interface role to 'Undefined' makes it possible to see the source under FortiView Sources:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.