Hello All,
I have FortiGate 601E, one of my outbound policy shows Active session about 15 but it doesn't show anything on the log when I do show matching logs on the policy.
Does anyone have any idea?
Thank you
Hi DrFirewall
By default the session is logged once it is closed, not before.
Hello AEK,
But the policy has Active sessions on it
Yes, this active session is not logged because it is still active. The session will be logged once it is closed (not active anymore).
Hi @DrFirewall24 ,
Please check using the following CLI commands:
If you have VDOM:
config vdom
edit <VDOM name>
// If you have no VDOM enabled, starting from here
config firewall policy
edit <ID>
show full | grep logtraffic-start
If it is disabled, all sessions hitting this policy will not be logged until the sessions expire.
User | Count |
---|---|
2261 | |
1230 | |
772 | |
452 | |
378 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.