thank you for sharing that debug flow snippet.
This is ICMP traffic (a ping?), correct? Do you have the same issue with other traffic? How long does it roughly take for the FortiGate to stop forwarding the traffic?
I would suggest you check the following:
- dia sniffer output, as @akumarr suggested, to verify if traffic is leaving the FortiGate and perhaps being dropped somewhere behind it
- DoS policies on the FortiGate, if you have them enabled -> they could cause ping to be dropped after a certain threshold is reached
- any forward traffic logs you have, to see if the traffic is denied for some reason or dropped by implicit deny
-> you might need to enable logging on implicit deny (right-click on the log setting for implicit deny in the policy table, then select 'All' and save)
-> debug flow might show some information regarding traffic being denied or dropped by implicit deny; if nothing is visible in debug flow, this suggests the issue might not be with policy matching but something else
A rough guide for initial troubleshooting for potentially blocked traffic may be found here: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Initial-troubleshooting-steps-for-tr...
Hope this helps :)
+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++