Created on
01-08-2026
10:45 PM
Edited on
01-09-2026
05:08 AM
By
Jean-Philippe_P
| Description | This article describes a scenario where traffic continues to match a firewall policy on a FortiGate even after the associated Virtual IP (VIP) has been removed. The article provides a step-by-step guide to resolving this issue by clearing existing sessions in the session table. |
| Scope | FortiGate. |
| Solution |
To resolve this issue, follow these steps:
Collect the debug flow and iprope list output for VIP rules before applying the above; this will make sure that the VIP is not in use for any policy:
diagnose firewall iprope list 100000
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.