Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
opifex
New Contributor

Output from diag debug flow filter

Hello, can anyone tell me what msg="Allowed by Policy-1:" means at the output of diagnose debug flow filter saddr ?

5 REPLIES 5
Toshi_Esumi
SuperUser
SuperUser

Means the packet arrived at your FGT is allowed to go out by firewall policy ID 1. Depending on your FortiOS version GUI might not show the ID by default and show only sequence. You might need to add ID into the table view. In CLI it always show up under "config firewall policy".

opifex

Thanks, "id" was disabled, but in the cli under firewall policy I did not think that "edit 1" corresponds to policy-1.

 

What is the difference between id and seq. # In the table?
Ashik_Sheik

Hi ,

 

When policy is created unique assigned ID which can be tracked by using this ID no.Sequence no mainly used in GUI to track the policy .But in cli only policy ID is used and even in the logs .

 

Regds,

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Toshi_Esumi

They even dropped from showing the sequence numbers in GUI from, I think, 5.6. Only IDs are in Firewall->IPv4 Policy.

Prab
New Contributor

opifex wrote:

Thanks, "id" was disabled, but in the cli under firewall policy I did not think that "edit 1" corresponds to policy-1.

 

What is the difference between id and seq. # In the table?

Policy ID -> An unique identifier assigned to a policy (firewall or an Explicit proxy). Does not change, unless the policy is deleted. For eg: Policy ID 0 is the default Deny policy. Please be aware that it is possible to have a Firewall policy with ID 1 and Explicit proxy policy with ID 1, as they are of different types.

 

Seq Number -> A number assigned to policy depending upon its position in the Policy Table. The FGT will match the traffic to a policy from top to bottom. This means from Seq No 1 to Seq no N. Seq 1 is the top. The Seq number will help you to plan how you position your policies. Generally the policy that catches the maximum traffic is moved to the top (lower Seq No.)

The Seq No. will change automatically, if you change the position of policy in the policy table. For eg: Dragging a policy in GUI.

 

Hope it helps,

Prab

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors