Hello everyone,
Is there a simulation tool in FortiGate where
1) you provide a source ip/port and a destination ip/port and service (maybe more parameters)
2) the tool returns you what policy, security profiles, etc and actions would be applied acoording to the current settings?
Thanks for your help,
Solved! Go to Solution.
Hello,
It exists and it is built-in in FortiOS (CLI/GUI). Please find the details about CLI tool following the link below:
Please find the details about GUI tool following the link below:
Hello,
It exists and it is built-in in FortiOS (CLI/GUI). Please find the details about CLI tool following the link below:
Please find the details about GUI tool following the link below:
Thanks. I get "Unkonwn action 0"
Fortigate1 $ diag firewall iprope lookup 10.187.1.100 12345 8.8.8.8 53 udp port2
Unknown action 0
Maybe I need to be administrator? I am on a readonly user
Hey joh2k,
yes, for the whole 'diagnose' commands you need to be an administrator; the diagnose commands can be pretty powerful and are thus locked behind admin privileges.
I believe you might still be able to use the policy lookup tool in FortiGate GUI though, as long as you have read permissions for that.
The administration guide link my colleague provided above contains a section about the Policy Lookup tool in FortiGate GUI.
I hope this helps!
Hello,
I tested in the lab (7.2.4 GA read-only admin). GUI and CLI worked just fine for me. Do you use VDOMs? Did you have a chance to check GUI?
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.