Running Fortigate on 6.2.3 and I have a policy set to basically allow all traffic and *sometimes* I get Deny: Policy Violation in the logs referencing this policy. What could be causing the deny? It does not happen all the time, just sometimes. Traffic is hitting the policy correctly.
config firewall security-policy
edit 35
set uuid <redacted>
set name "Outbound Allow Everything Else"
set srcintf "Trust"
set dstintf "virtual-wan-link"
set srcaddr4 "all"
set dstaddr4 "all"
set enforce-default-app-port disable
set service "ALL"
set action accept
set schedule "always"
set logtraffic all
next
end
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Where are you seeing the deny ? if it's denied it did not 1> match that policy 2> match a "deny" policy or 3> the implicit "deny" or 4> the protocol was scrub and found in violation.
Paste logs that you are viewing that shows the deny.
Ken Felix
PCNSE
NSE
StrongSwan
The deny message was first spotted in the forward traffic log and the entry referenced deny because of that specific policy (35). However, I have since updated to 6.2.4 and those deny hits seems to have gone away.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.