No, I just installed the FG, set the hostname, IP addresses of WAN, LAN1 and LAN2 interfaces, allowed ping on all interfaces but http/https only on the WAN, set the LAN1 as DHCP server, and changed the settings to policy based. The rest is the configuration by default (only the deny all policy exists). If it helps, it's a KVM virtualized FG, but I think it should not be important.
I thought about doing debugging it, but the thing is that it should not match anything. Tomorrow I will if I don't find any logic behind it.