Hi,
Let's say we have 2 firewall policies, 1st policy said that user AAA can access to Streaming websites only, other categories website all blocked. 2nd policy said that user AAA can access to free software download websites only, other categories website all blocked. So the question here is user AAA can access to free software download websites or not? because the firewall policy check is from top to bottom, if the 1st policy hit and deny the traffic for free software download, then will it go to 2nd policy?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
No it's top down, 1st match. fwiw; the diag debug flow cmd will show you want policyid is being match and the action. It's isn't like a try all policies until you get thru ;)
PCNSE
NSE
StrongSwan
indeed as a policy lookup going trough when he match the 1st policy that deny software downloads he won't go further as emnoc say :p
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.