Skip to main content
AD Academy
Network security: Fortinet
Intermediate16 minLast updated: Topic 4 of 14

Firewall policies and objects

How a policy is built, the order it is evaluated in, and why objects save dozens of rules.

Not read

What you will learn here

  • How a Firewall Policy is built
  • In what order rules are checked
  • Why objects save work

Worth reading first:What are FortiGate and FortiOS?

All traffic through FortiGate is matched against the policy table top-down. The first matching rule wins. If nothing matches, traffic is dropped by the implicit deny rule.

The packet enters an interface, passes DoS and IP integrity checks, then session lookup: if a session already exists it takes the fast path with no policy re-match. Otherwise policies are scanned top-down, first match wins, and with no match the implicit deny (ID 0) drops it. Then NAT, UTM inspection and egress through the interface chosen by the routing table.

Short and clear

  • Only the first packet of a flow walks the full chain; the rest ride the existing session.
  • Policies are scanned top-down — first match wins, so rule order is critical.
  • No match = implicit deny (policy ID 0); the packet is dropped, by default without a log.
  • NAT and UTM only run after a policy has matched.

Real-life exampleYou added an allow rule and nothing changed: a broad deny sits above it. Use move to raise the policy, then diagnose sys session clear so the old session stops following the previous decision.

Policy building blocks

  • Incoming / Outgoing Interface — where traffic enters and exits (or a Zone).
  • Source / Destination — address objects, groups, users or ISDB entries.
  • Service — port/protocol (HTTP, RDP, ALL).
  • Action — ACCEPT or DENY, sometimes IPsec.
  • Security Profiles — AV, , Web Filter applied to the permitted traffic.
  • Log Allowed Traffic — without it you will see nothing during an investigation.
config firewall policy
  edit 0
    set name "LAN-to-Internet"
    set srcintf "internal"
    set dstintf "wan1"
    set srcaddr "LAN_SUBNET"
    set dstaddr "all"
    set service "HTTP" "HTTPS" "DNS"
    set action accept
    set schedule "always"
    set nat enable
    set logtraffic all
  next
end
text

Check yourself

What happens to traffic that matches no policy?

Was this page helpful?