Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

How can I change policy action to " reject"

Hi All, I saw Firewall policy default action are " accept" , " deny" , " ip-sec" and " ssl-vpn" . Because deny action default is dropping packet and don' t let user know that. But I want action that " reject" drop packet and let user know. Are there any idea about this ? thanks
5 REPLIES 5
UkWizard
New Contributor

A reject option would not let the user know as such, it would simply reply to the initial TCP connection to say its rejected. So unless you have an app that uses this specific technique, the reject only really increases the timeout window. as the connecting program knows its quit immediately, rather than waiting to the end of the timeout. Reject is less efficient and therefore not really required. Hope this makes sense, in essence, if a user is web browsing, they would get the same message in the browser anyway i suspect.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Because I don' t want user browse blocked web that wait for too much time getting time out information. I think user can get blocked information if policy action is " reject" . And Some app program would auto connect blocked webs when opening and it would waste much time to wait for connect if I set policy action to " Drop" . So if I can set action to " reject" that the app program whether it can open quickly. Thanks
UkWizard
New Contributor

users wouldnt get a nice message generally, they would get an error, just like when the website they are trying to browse to is down. A reject is not possible in fortinet, sorry. if you wanted the users to get nice fortinet-generated messages when a website is unaccessible, then you would need to use web-filtering in your profile, then they will get the fortinet page saying blocked etc..
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

got it!!~ Thanks for your suggestion~
Not applicable

I have another question is why Fortinet don' t add " reject" function ? FortiOS is build on Linux and it should be easy to add " reject" function. thanks
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors