Most FortiGate issues come down to three causes: the policy did not match, routing sends traffic the wrong way, or a security profile is blocking. A fixed checking order saves hours.
- 1. Log & Report → Forward Traffic — check whether the packet arrived and which policy ID handled it.
- 2. Routing — verify a return path exists; without it the reply disappears.
- 3. Sniffer — see whether packets physically reach the interface.
- 4. Debug flow — follow the internal decision for each packet.