The Willhouse

Home

❯

TheWillhouse

❯

Notes

❯

Forti

❯

Forti Policy checking for CDECPE

Forti - Policy checking for CDECPE

Apr 30, 20261 min read

  • fortigate
  • firewall
  • networking
  • cli
  • troubleshooting

📅 Wednesday, 5 February 2025

🕐 11:00 AM

iprope shows what policy is being hit, use this command:

diagnose firewall iprope lookup SOURCEIP PORT DESTIP PORT UDP/TCP INTERFACE

  • In an example, I could see that the traffic was hitting policy 0 which is an implicit deny. Even tho the above command showed this, we still ran a debug to confirm

Related Notes

  • Forti - Session filter to find network path & find NAT
  • Forti - Checking logs
  • Firewall Troubleshooting Guide

Graph View

Backlinks

  • Forti - Checking logs
  • Forti - PCAP without live user
  • Forti - Session filter to find network path & find NAT
  • Forti
  • FAZ (FortiAnalyzer)
  • Firewall Troubleshooting Guide
  • What is NAT
  • Index

Created with Quartz v4.5.2 © 2026

  • GitHub
  • Discord Community