Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

firewall count

Under firewall->policy, I find a ' count' option, what' s function? For understanding my fgt-60 loading, can I calculate the firewall throughput by this count?
8 REPLIES 8
MasterBratac
Contributor

Which firmware version do you use ... I´ve never seen that ... screenshot?
p768
New Contributor

The FortiGate unit counts the number of packets and bytes a firewall policy is hit. For example, 5/50B means that a total of five packets and 50 bytes has hit the policy. The counter is reset when the FortiGate unit is restarted or the policy is deleted and re-configured.
Carl_Wallmark
Valued Contributor

Hi, Count was introduced in MR6 i think, it prints out packets/MB for each firewall policy

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
abelio

Hi, Count was introduced in MR6 i think, it prints out packets/MB for each firewall policy
Hi, it was introduced with MR4; from releasenotes: " Firewall Policy Packet and Byte Counter MR Introduced: FortiOS v3.00 MR4. Description: The FortiGate now can count the number packets and bytes a firewall policy is hit. The feature is enabled in each policy and the counter is viewable from the firewall policy list page. The column is not shown be default. The counter is reset when the FortiGate is restarted, if the policy is deleted and re-configured, or by using the " diagnose firewall iprope clear group <index>" CLI command.

regards




/ Abel

regards / Abel
MasterBratac
Contributor

Ahh ... cool ... found it ...
laf
New Contributor II

I discover it too in MR6 but it is present since MR5 patch 3 I think. It s pretty useful to see unused firewall policies, to debug VPN interface mode ping and so on. I also opened a ticket to Fortinet about this feature from CLI, but they re reluctant to answer me :). It' s possible to see it too from CLI, it s just it s a bit complicated. I asked them for some clarification on this, but..no answer ' till now.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
rwpatterson
Valued Contributor III

One thing that sux about it is that the only way to reset it is to disable/enable the policy....

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
laf
New Contributor II

One thing that sux about it is that the only way to reset it is to disable/enable the policy....
Why' s that so annoying to you? You also can restart the equipment to get the same effect ;)).

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors