Hello Fortinet Community,
I am trying to implement cumulative traffic quotas per IP on a FortiGate device. The goal is to:
I understand from Fortinet TAC that FortiGate does not natively support data-volume-based traffic shaping over a time period. I have explored web-filter quotas, but they are daily, category-specific, and require proxy mode, which is not suitable for our use case.
My question is:
Is it possible to achieve this using Forti Analyzer automation or event handlers?
If yes, can someone provide guidance or example configurations?
Are there any recommended best practices or workarounds to enforce per-IP monthly data quotas?
Note: FortiGate Version is 7.4.8 and so is FAZ.
Thank you in advance for any advice or guidance.
Best regards,
FortiAnalyzer Event Handler can only trigger a stitch if: say sent/received bytes reach the 6TB limit but the 'Action' to limit and throttle is NOT controlled by FAZ.
I am not sure how would you throttle on the FGT, if there is a CLI command on FGT that can do it then you can set it up in 'Action' for the Event Handler.
Thank you for the clarification. That makes sense ,if Forti Analyzer can only trigger the event but not enforce shaping directly, the challenge is finding a FortiGate-side action that can apply per-IP throttling dynamically.
From what I can see, FortiGate doesn’t currently offer a CLI command to modify traffic-shaping policies on a per-IP basis on the fly, which limits what an Event Handler can actually automate. It seems the missing piece is the ability to programmatically adjust shaping rules once the quota is hit.
I appreciate your input; this helps confirm the limitations and keeps me from going down the wrong path. If anyone has found a creative workaround or script-based method that can reliably enforce per-IP monthly quotas, I’m still very interested.
Thanks again!
| User | Count |
|---|---|
| 2883 | |
| 1446 | |
| 844 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.