Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gertyl
New Contributor

The policy does not work on FortiGate

I modified the policy on FortiGate by adding a new port to it. Since traffic began to be forwarded through this port, I saw in FortiAnalyzer that traffic through this port falls under policy ID 0, meaning it is blocked. At the same time, I checked the source and destination IP addresses in the logs—they are specified in the policy.
I found information that this is because the session is currently active, but I looked at the information in the policy, which showed the number of active sessions, and it dropped to 0, then rose again.
Has anyone encountered something similar?
I would be very grateful for your help.

Version of FortiGate: 6.4.15

3 REPLIES 3
gertyl
New Contributor

I compared the traffic information that previously passed through another port with the current traffic and found that the only difference is in the destination interface.
Please advise what can be done in this case.

princes
Staff
Staff

Hi,

 

Kindly verify the services allowed in policy as well.

If it is all then collect the debug output for the same:

 

diagnose debug flow filter addr <destination-ip>

diagnose debug flow show function-name enable

diagnose debug flow trace start 100

diagnose debug enable

 

This will give more insight .

 

Thank you.

Regards,

Prince

 

 

Best regards, Prince singh Fortinet EMEA TAC Engineer
princes
Staff
Staff

Hi,

 

Also verify if the server accepts the connection only from a specific outgoing interface IP.

This could create problem with another outgoing interface IP if SNAT is performed and new interface Ip is not whitelisted on destination.

 

Thank you.

 

Regards,

Prince

 

Best regards, Prince singh Fortinet EMEA TAC Engineer
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors