FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
adimailig
Staff
Staff
Article Id 366753
Description This article describes how to determine the Virtual IP ID used by incoming traffic.
Scope FortiGate.
Solution Use debug flow commands to debug the packet flow with show iprope and function enable.

diag debug flow show iprope enable

diag debug flow show function enable

Flow filters can also be added to narrow down the traffic. See the below link for a list of filter options:
Debugging the packet flow

Debug output will show a matched DNAT/Virtual IP ID. In the below example, the Virtual IP ID (vip) is '4'.

debug flow vip.JPG

Cross-reference the Virtual IP ID via GUI.

GUI_VIP.JPG
Contributors