Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mlourenco
New Contributor

Forward Traffic and Local Traffic in Log & Report section

Hello,

 

I have a fortigate 100D.

 

Can you tell me the difference between forward traffic and local traffic in Log & Report section?

 

 

 

 

 

 

1 Solution
Debbie_FTNT

Hi Mlourenco!

 

Local traffic is traffic destined for any IP on the FortiGate itself -> management IPs, VIPs, secondary IPs etc.

Any traffic NOT destined for an IP on the FortiGate is considered forward traffic.

 

Regarding local traffic being forwarded:

This can happen in cases of VIP and similar setups. We have traffic destined for an IP associated with the FortiGate itself (the external IP of the VIP), and the FortiGate will do DNAT to the internal IP and then forward the traffic to the internal IP. It will still be considered local traffic, because the initial traffic (prior to DNAT) is addressed to the FortiGate directly.

 

Does this clear up the confusion?

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

4 REPLIES 4
rwdorman
New Contributor III

Local traffic is traffic directed to the Fortigate itself on one of its management interfaces.  Forward traffic is that traffic permitted or denied by a firewall policy. (and "forwarded" to its destination)

-rd 2x 200D Clusters 1x 100D

1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D

-rd 2x 200D Clusters 1x 100D 1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D
mlourenco

But, local traffic can be forwarded also? What's the diference between both?

Debbie_FTNT

Hi Mlourenco!

 

Local traffic is traffic destined for any IP on the FortiGate itself -> management IPs, VIPs, secondary IPs etc.

Any traffic NOT destined for an IP on the FortiGate is considered forward traffic.

 

Regarding local traffic being forwarded:

This can happen in cases of VIP and similar setups. We have traffic destined for an IP associated with the FortiGate itself (the external IP of the VIP), and the FortiGate will do DNAT to the internal IP and then forward the traffic to the internal IP. It will still be considered local traffic, because the initial traffic (prior to DNAT) is addressed to the FortiGate directly.

 

Does this clear up the confusion?

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
vivianwu_FTNT

Local traffic includes traffic destined for any IP on the FortiGate itself (such as management traffic ) or traffic initialized from Fortigate itself (such as traffic to Fortiguard)

 

forward traffic is the traffic through Fortigate

Labels
Top Kudoed Authors