Description | This article describes how to match the traffc in debug flow output to an SD-WAN rule. |
Scope | FortiGate. |
Solution |
To match debug flow output to an SDWAN rule, run diag firewall proute list and match it to the debug flow. Match the ID in the proute list to the policy routing id=2131230723.
For example:
Debug flow output snippet: Technical Tip: Debug flow tool
id=65308 trace_id=11 func=iprope_dnat_check line=5505 msg="result: skb_flags-02000000, vid-0, ret-no-match, ac
diag firewall proute list id=2131230723(0x7f080003) vwl_service=3(internet) vwl_mbr_seq=1 dscp_tag=0xfc 0xfc flags=0x0 tos=0x00 tos_mask =0x00 protocol=0 port=src(0->0):dst(0->0) iif=0(any) path(1): oif=3(port1) path_last_used=2025-02-27 06:04:59 source(1): 0.0.0.0-255.255.255.255 destination(1): 0.0.0.0-255.255.255.255
Matching the ID in 'diag firewall proute list' to the ID in the debug flow will reveal that it matches the SD-WAN rule vwl_service=3, which is rule 3.
This is the screenshot showing the rule that is matched on the GUI. |