All traffic through FortiGate is matched against the policy table top-down. The first matching rule wins. If nothing matches, traffic is dropped by the implicit deny rule.
The packet enters an interface, passes DoS and IP integrity checks, then session lookup: if a session already exists it takes the fast path with no policy re-match. Otherwise policies are scanned top-down, first match wins, and with no match the implicit deny (ID 0) drops it. Then NAT, UTM inspection and egress through the interface chosen by the routing table.
Policy building blocks
- Incoming / Outgoing Interface — where traffic enters and exits (or a Zone).
- Source / Destination — address objects, groups, users or ISDB entries.
- Service — port/protocol (HTTP, RDP, ALL).
- Action — ACCEPT or DENY, sometimes IPsec.
- Security Profiles — AV, , Web Filter applied to the permitted traffic.
- Log Allowed Traffic — without it you will see nothing during an investigation.