Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Robert_Cerny
New Contributor II

Firewall LEARN rule

Hi folks,

does anybody know how much time/traffic needs LEARN rule to actually show anything in the Log? I have it set up for 5 days and 30GB of traffic went through but still don't see any result.

FG-100C FG-100A FW-50B FG-60C
FG-100C FG-100A FW-50B FG-60C
10 REPLIES 10
emnoc
Esteemed Contributor III

Qs:

 

What do you mean by learn rule?  have  you conduct any "diag debug flow" commands to validate that traffic is actually hit that rule that you suspect?

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Robert_Cerny
New Contributor II

LEARN rule is the new thing in FortiOS 5.4.1. You have another fw rule to ACCEPT and DENY named LEARN, which checks packets and according to docs after some time shows its results in Log & Report pane.

 

[link]https://www.youtube.com/watch?v=LI3bW2eO-ck[/link]

FG-100C FG-100A FW-50B FG-60C
FG-100C FG-100A FW-50B FG-60C
MikePruett

Emnoc is right. Can you verify that traffic is truly hitting this policy? Chances are it needs to be higher up on the policy set as an existing policy may be letting the traffic traverse before it gets down to the learn rule you created.

Mike Pruett Fortinet GURU | Fortinet Training Videos
MikePruett

The learn rule is most useful (to me at least) when deploying a new fortigate in an environment using an ASA or whatever. Throw it in line in transparent mode and from there let it learn. Then you can make the policy in NAT mode and use it to replace the existing device.

 

Mike Pruett Fortinet GURU | Fortinet Training Videos
Robert_Cerny

It's the only rule which is active on device. And as I wrote already, more than 30GB went through this rule. Should I consider it as a bug?

FG-100C FG-100A FW-50B FG-60C
FG-100C FG-100A FW-50B FG-60C
emnoc
Esteemed Contributor III

Could  be a bug 

 

1: try deleting it

2: re applying

 

or another rule that's specific for example like ICMP and see what happens

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
MikePruett

Sorry, It's Monday haha. I would think it would have shown something by now. I will deploy one in my lab tonight and see what happens. 

Mike Pruett Fortinet GURU | Fortinet Training Videos
emnoc
Esteemed Contributor III

just seen this tidbit in the rls notes:

 

 

 

Because this feature requires a minimum level of logging capabilities, it is only available on FortiGates with hard drives. Smaller models may not be able to use this feature.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Robert_Cerny
New Contributor II

Oops,

good find. I think Fortinet should disable these kind of options in GUI, it's just confusing people.

FG-100C FG-100A FW-50B FG-60C
FG-100C FG-100A FW-50B FG-60C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors