Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MORAMADAN
New Contributor III

Fortigate 7.4 series rule source match logic

Hello Team, 

   I wanted to know if i have configured my fortigate firewall with source user accounts of user1, user2 and user3, and ip addr1, and ip addr2,and mac addr1, mac addr2, and mac addr3.

How firewall will process the source match logic according to the source objects and type mentioned above User accounts, IP addresses, and mac addresses?

TIA

M.Ramadan
M.Ramadan
2 REPLIES 2
distillednetwork
Contributor III

If you have a user defined in the policy, it based on how you have auth-on-demand set.  

 

config user setting
    set auth-on-demand <always|implicitly>
end
 
By default, it will skip the policy and only come back to it if nothing else matches.  Here is a Tech Tip on it:
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
MORAMADAN

Thank you @distillednetwork for the reply and link.

I wanted to know assuming users are authenticated, and with all ojects in the source field mentioned,  how the fortios think about source matching?

The AND OR logic among them in matching probability.

M.Ramadan
M.Ramadan
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors