- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Traffic match with wrong Schedule
Foritgate FW version : 7.4.4
I have created two proxy policy with different schedule, office hour and non office hour.
and i notice that the traffic is matched with non office hour schedule and policy when I access internet in office hour.
anyone have experience this issue ?
Observed Update on 8/July/2024:
Traffic between 4PM to 3 AM will go to office hour policy with schedule 8AM-7PM
Traffic between 3AM to 4 PM will go to non office hour policy with schedule 7PM-8AM
- Labels:
-
FortiGate
-
Proxy policy
-
Schedule
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sry are you replied a wrong post...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @itmdadmin,
I can't reproduce this issue in my lab. Please check FortiGate timezone and make sure it is correct. You can also collect debug flow to see if it really matches that policy. https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
Created on ‎07-07-2024 11:23 PM Edited on ‎07-07-2024 11:24 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Timezone is correct and I have worked with a foritgate engineer to troubleshoot it but still not solved and the case is under researching....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Can you verify source and destination in policy look up and Check to see there are no other firewall rules that supersede this rule. Remember that firewall rules are processed from top-to-bottom.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
there is no other policy that will supersede those two rules
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what I see is that your one schedule's ending time is exactly the start time of the other and vice versa.
Probably this might result in sessions being created with wrong policy because both are active for that minute and then the first will match?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
we had try setting the start time and end time with 1 min different but still the same result.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
- Do you see the issue all the time or only for a specific period of time every day?
- Is the "fast-policy-match" configuration enabled in the Firewall?
Regards,
Shiva
