Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
danielha
New Contributor

FortiOS 5.2 logging : action=dns or action=ip-conn

Hi all, The LogReference PDF file does not give complete information regarding the action in the logs. Can someone give me more information about the action ? action=deny : no problem. We hit a deny rule in the firewall policy action=start : the log is created at the very begining of the tcp session. This is for debugging. action=timeout : the session duration hits the firewall timeout. The firewall closes the session. action=close : the log is created at the end of the session (when a tcp FIN packet is seen ?) action=ip-conn : what difference with action=close ? action=dns : I can' t figure out the meaning... Thanks for your help, Daniel
10 REPLIES 10
AtiT
Valued Contributor

Hello Jeff,

The sent/received packets are: 0/0. I the pakcet is lost before reaching the firewall there will be no log. Otherwise sent packets will be different from 0 and received will be 0 when the return packet is lost.

AtiT

AtiT
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors