Hi
Fortigate 800D
v5.6.4
Configuration:
External Public IP addresses range in configured as a secondary range on one of the fortigate interfaces.
We took one IP from that range and configured it as a Virtual Server LB to 4 internal servers exists behind another interface.
See topology attached.
Then we configured 2 policies:
1- from interface 1 to interface 2 to IP 2.2.2.1. (2.2.2.1 as IP address object , NOT virtual server)
2- from interface 2 to interface 3 to the virtual server 2.2.2.1
we see counter/policy hits on policy number 2
but we don't see counter/policy hits on policy number 1
we thought at first that we don't need policy 1 , but after deleting it , no one was able to connect to the virtual server.
So policy 1 is necessary but it is not showing counter and no logs showing in fortianalyzer/diag debug regading policy 1
should the counter work and maybe this is a bug ?
or it should not work ...
Can anyone explain this to me ?
Thanks
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Verify you have "All Sessions" logged on the policy
From the CLI:
diagnose sys session filter policy <policy id>
diagnose sys session list
If sessions open indefinitely they will not show up in the logs, you can force the sessions to close by using:
diagnose sys session clear
However, make sure you have a filter set otherwise you will clear all sessions.
Hi,
The log is set to log all session.
And regarding the diagnose command it shows total session 0
FGT1 # diagnose sys session list
total session 0
Thanks
Run this using the source IP address you are testing connections from and it should help you identify which policies the traffic is hitting:
diagnose debug reset diagnose debug enable diagnose debug flow show console enable diagnose debug flow filter addr <source ip> diagnose debug flow trace start 100 To stop the debug: diagnose debug disable diagnose debug reset
Hi
Thank you, but I know all of this.
And as I mentioned earlier: "and no logs showing in fortianalyzer/diag debug regading policy 1"
So logs are not even displayed in the diag debug
Also notice that I'm running v5.6 , So '"diagnose debug flow show console enable"' is not gonna work there
Thanks
Flow and sessions/logs are not the same, excluding the show console command the rest will work as displayed.
If you are not seeing the traffic in the flow then it is being handled by the NPU. You can turn off NPU offloading in the policy to make sure you can see the traffic in the flow.
Another tool to use is: diagnose sniffer
I know how the diag debug works , I know how sniffer works.. I tested all this stuff before writing this post
As I said before , it is not displaying any log regarding policy 1
So logs regarding policy 1 is not displayed in any place ...
My basic question, have you encountered this issue in your environment ?
It is a little bit confusing configuration thats why I suspect this is a bug with this kind of configuration ..
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.