Hi folks,
does anybody know how much time/traffic needs LEARN rule to actually show anything in the Log? I have it set up for 5 days and 30GB of traffic went through but still don't see any result.
Qs:
What do you mean by learn rule? have you conduct any "diag debug flow" commands to validate that traffic is actually hit that rule that you suspect?
PCNSE
NSE
StrongSwan
LEARN rule is the new thing in FortiOS 5.4.1. You have another fw rule to ACCEPT and DENY named LEARN, which checks packets and according to docs after some time shows its results in Log & Report pane.
[link]https://www.youtube.com/watch?v=LI3bW2eO-ck[/link]
Emnoc is right. Can you verify that traffic is truly hitting this policy? Chances are it needs to be higher up on the policy set as an existing policy may be letting the traffic traverse before it gets down to the learn rule you created.
Mike Pruett
The learn rule is most useful (to me at least) when deploying a new fortigate in an environment using an ASA or whatever. Throw it in line in transparent mode and from there let it learn. Then you can make the policy in NAT mode and use it to replace the existing device.
Mike Pruett
It's the only rule which is active on device. And as I wrote already, more than 30GB went through this rule. Should I consider it as a bug?
Could be a bug
1: try deleting it
2: re applying
or another rule that's specific for example like ICMP and see what happens
PCNSE
NSE
StrongSwan
Sorry, It's Monday haha. I would think it would have shown something by now. I will deploy one in my lab tonight and see what happens.
Mike Pruett
just seen this tidbit in the rls notes:
Because this feature requires a minimum level of logging capabilities, it is only available on FortiGates with hard drives. Smaller models may not be able to use this feature.
PCNSE
NSE
StrongSwan
Oops,
good find. I think Fortinet should disable these kind of options in GUI, it's just confusing people.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.