Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
netengwi
New Contributor

Fortigate 60E with 5.4.4 Changes to Policies not being enforced until reboot

I have had a couple of our Fortigate 60E firewalls (5.4.4) exhibit an issue where changes to the iPV4 policies are not actually applying until a reboot.  If I make a new rule or add services to an existing rule the changes appear in the GUI and CLI but the new rules are not applied to any traffic. 

 

Example:

 

1. Created a service for TCP Port 10020.

2. Modified an existing firewall rule to add this as an allowed service.

 

Result

Traffic still blocked to 10020.  After rebooting the firewall the rule applies correctly.

 

Additionally, in some of my testing I created a new rule to allow all traffic and put it as the first entry in a policy.  The byte counter never increments and in FortiView it shows all of the connections are still using the policies below the new one.  Even if I disable the policies and delete existing sessions, new sessions show up using the disabled policies.  I have even tried disabling a VLAN interface that was part of a policy and re-enabling it to see if that would force the changes to actually be enforced.  This didn't work either.  Only a reboot results in the add/remove/changes actually applying properly.

 

Is there any other thing I can try apart from rebooting the firewall to force the policies to re-apply?

 

Sincerely,

 

Shane

10 REPLIES 10
poundy

Ahmad Hashem wrote:

How can I raise a new support ticket? Can you give the right link to start with? 

[link]https://support.fortinet.com/Account/Profile.aspx[/link]

Labels
Top Kudoed Authors