FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
bksol92
Staff
Staff
Article Id 328235
Description This article describes what to do when FortiManager is not reflecting policy hitcounts.
Scope FortiManager.
Solution

FortiGate is showing hit counts for a firewall policy:


hitcount-fgt.PNG

 

However, the hit count is not synced with FortiManager even when it is refreshed:

 

uuid-fmg.PNG

 

This is due to the difference in policy UUID between FortiGate and FortiManager:

 

uuid-fgt.PNG

 

Policy UUID on FortiGate: 244e8db8-4287-51ef-72f7-a18c9292e0fc.

 

Policy UUID on FMG: 244e8db8-4287-51ef-72f7-a18c9292e0fd.

 

FortiManager maps policy-related information retrieved from FortiGate such as hit count and bytes to policies with corresponding UUIDs. To make sure hit count is synchronized, policy UUIDs must be synchronized as well by either installing them from FortiManager or importing them from FortiGate.

 

uuid-install.PNG

 uuid-fgt-2.PNG

 

Related article:

Troubleshooting Tip: FortiGate is Out-of-sync in the Device Manager