Hi Community,
can someone explain the meaning of "ret-no-match" in a debug flow on a FGT?
As an example debug line see the following:
"2022-07-01 09:04:45 id=20085 trace_id=32985 func=__iprope_check_one_policy line=1951 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept""
I understand the line itself but not the meaning of "ret-no-match".
Thanks a lot.
Kind regards
Dominik
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @kcheng
Thanks for the fast reply!
But how can the action be "act-accept" if the match is "ret-no-match"?
Kind regards
Dominik
Hi @PampuTV
The respective means that based on the firewall policy check, the traffic has no match on policy 6. So the check result return no match (ret-no-match).
Hi @kcheng
Thanks for the fast reply!
But how can the action be "act-accept" if the match is "ret-no-match"?
Kind regards
Dominik
Hi @PampuTV
The action is referencing the action set on the firewall policy, but not the action taken after the traffic is being evaluated against policy 6. Policy 6 is permitting traffic if it matches the policy. based on the debug flow filter, your traffic does not match firewall policy 6, so it will continue to get evaluatedd by the next policy.
Hi @kcheng
understood that, thanks.
Can you maybe tell if "policy 6" is based on a firewall policy or a firewall security-policy? Talking about NGFW mode exclusively.
Kind regards
Dominik
Hi @PampuTV
The debug flow would show policy on native policy only. That means it is under firewall policy. There is another command to debug on security policy. You may refer to the KB below:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.