Hi all,
Have a quick question, couldn't really find anything when searching around. I created a new policy package, added a few rules, and pushed out to the FGT. All is working well. In FortiManager, I see the Implicit Deny rule which was created during policy package creating. But when I log on to the Fortigate itself, I don't see the Implicit Deny rule under the policy. I can view all other rules which were added afterwards. Is there some settings or config to enable viewing of this Implicit Deny rule? It's rather odd. We have other setups, running the same version OS, from the same FortiManager, and when logging on to those firewalls directly, I can see the deny rule. Any ideas why I can't see it, as I'm not really sure if it's being enforced or not, maybe its hidden, but I can't see anywhere to unhide it from the GUI. Running fortios 6.0.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
First of all I don't think the implicit deny policy you see in GUI either FMG or FGT exists in the config. As a matter of fact, if you download the whole config and look at the "config firewall policy" section, you never find the policy there.
I think it's just a reminder in GUI any traffic that matches none of those policies above would be silently dropped.
If you see on 6.0 GUI at some of FGTs while don't seem at other FGTs, I would think it's a GUI bug unless they have changed the look with 6.0.x and you don't see on <x and you see on >x.
In any case it's just cosmetic, which I would ignore.
Right, but as I mentioned, other FGTs running 6.0 have the implicit deny rule on the fortigate showing under the ipv4 policy. For this one in particular, its only visible on the policy package in fortimanager, not on the fortigate itself. I know it's only a visual thing, but I'm curious and want to know why its not showing on the actual fortigates policy.
I have to agreed with the previous poster, that the rule is not in the webUI and obviously not in the cfg. It's policyid #0 for reference.
Now that I think about it, the only firewalls I know that shows a implicit deny is and in some case you defined the implicit rule or cleanup rule.
e.g fw that shows implicit deny
CHKP
PANW
forcepoint iirc
To be quite frank, I never notice the present of the rule not in the webUI.
Ken Felix
PCNSE
NSE
StrongSwan
Open a case at TAC against the FGT that doesn't show.
I actually figured it out, it's now appearing. I originally had all of the rules dumped in one place without a section header. Because the Implicit Deny rule is in a section header of it's own, this could be why it wasn't appearing. Once I added a section header for all of the rules in place before the deny, and pushed it to the FGT, the Implicit Deny, along with it's section header appeared.
I'm not sure what you meant with "section header" (maybe additional sections to interface pairs). But any GUI appearance settings on the FMG shouldn't affect to the appearance on the FGT GUI. Especially it's not consistent through multiple FGTs.
The rulebase originally had no section created. So all rules were deployed without a section defined. In FMG, the rules were visible in the open, while there was a section called "Implicit" with the implicit deny rule with in. On the FGT, only the rules were visible, with no section (originally). Once I created a section for the rules and pushed these changes out from the FMG to the FGT, the implicit section and implicit deny rule appeared on the fgt. So something around the fact that there was no other section created, is what caused the imp deny rule not to appear in the gui on the FGT. Case closed.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.