Have to toss it back and forth with the folks here and think about what this will do in terms of log load. I have implicit deny logging enabled but for whatever reason when I use a VIP with port forwarding it seems to no longer log the denied traffic that had a destination IP of the firewall interface. This is valuable in providing a quick snapshot to determine if you need to dig deeper into the traffic that is hitting this policy. The second policy is supposed to act as an implicit deny for all other traffic attempting to authenticate with our IPSEC VPN. My question is whether or not the actual "Policy ID 0" is the implicit deny rule and if it is why am I seeing logs from it because I shouldn't as far as I can tell. how to identify the origin of this ? To allow any traffic through FortiGate on any port, configure the IPv4 policy with 'action' set to 'Accept/Permit'. I think we're headed in the right direction! Optional: You can create deny policy and log traffic . That would just about wreck the logs/SIEM server though if that was the case though so pros and cons for sure.

In this case I noticed this while setting up a proof of concept for a SIEM solution (the Fortinet one). Oftentimes this is a good way to find custom ports or protocols that may have been overlooked as a part of the implementation process and could have been causing your users heartache. This is true for any traffic allowed through your firewall and out to the internet, but this is even more true when it comes to denied traffic. A Firewall Policy with action = DENY is however needed when it is required to log the denied traffi c, also called "violation traffic".

0515255 was my bug report. See related articles for more information about Firewall Policies. By default, this In my experience, only in special cases one is interested to see denied traffic, mostly while troubleshooting. Its as if there is no implicit deny for these local in policies or something. Is the Policy ID 0 represents "implicit rule" of the firewall ? Im not seeing how these IP addresses could try and authenticate when I specified a small group of public IP addresses that are allowed. Hey everyone, Hoping you can clarify something for me.