Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luckyle
New Contributor

Firewall Policy seems to be not working...

Hi there,

I am having FGT310B running OS5.2.3 build670, I just finished FSSO and then add SSO user into a policy but fw policy seems to be not working, I tried to mark 'Deny' to the policy (ID 36, pls. take a look the pix) but nothing, it affected only on ID 28 policy but FSSO not working too.

So what is something wrong to me?

Thanks

luckyle
luckyle
3 REPLIES 3
Christopher_McMullan

I'm not quite sure I understand. Given the screenshot, policy ID 28 would be matched first.

 

In 5.2, the user/device identity was taken into account alongside addresses, schedule, and service, but the list in general is still more-specific-to-more-general, top-down, first match.

Regards, Chris McMullan Fortinet Ottawa

emnoc
Esteemed Contributor III

I agreed ,  but you should use diag debug flow and validate what policy is being matched. If it's match by the higher  up policy than #36 will never come into play.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
luckyle
New Contributor

I will, but i think the #36 will never working, btw all #id that i copied from another interface, #36 was new created...
luckyle
luckyle
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors