Methodology: Test Before Tuning
Do not start changing firewall rules until you have confirmed exactly where traffic is being blocked. FortiGate has excellent built-in diagnostic tools.
Step 1: Policy Lookup Test
Navigate to Network then Diagnostics then Policy Lookup.
Enter source IP, destination IP, destination port, and protocol. FortiGate will show exactly which policy would match.
If no policy matches, traffic is implicitly denied — add the missing rule.
Step 2: Packet Sniffer (CLI)
From the CLI, run the sniffer to see if traffic is arriving at the firewall. If you see packets arriving but none going out, the firewall is dropping them.
Step 3: Debug Flow (CLI)
Enable debug flow to trace exactly what the firewall does with a packet. Look for policy check failures or reverse path check failures.
Common Causes and Fixes
| Symptom | Likely Cause | Fix |
|---|---|---|
| Specific website blocked | Web filter category | Add URL exception |
| App traffic blocked | Application control | Add application exception |
| All traffic blocked after change | Policy ordering | Move policy higher in list |
| Intermittent drops | IPS blocking legitimate traffic | Check IPS logs, add bypass |
| VPN connected but no access | Split tunnel or route | Add route to VPN phase 2 |
IPS False Positive Check
Navigate to Log and Report then Intrusion Prevention. Filter by source IP. If legitimate traffic is being blocked, add an IPS sensor override for that signature.
Useful CLI Quick Reference
- get system performance status: CPU and memory overview
- get router info routing-table all: routing table
- diagnose sys session list: active sessions
- execute ping from specific interface: use ping-options source before execute ping
Related: Networking and Security Dubai | Managed IT Services Dubai
Tags
About the Author
Reviewed by Mustafa Husain, Founder of SAS IT Services, with 10+ years of experience in IT infrastructure, networking, and security — alongside the same engineers who design, install, and support the work described on this site. SAS IT Services was founded on 22 February 2020 in Dubai and has since delivered 500+ projects for businesses across the UAE.
We specialize in Fortinet, Cisco, and Microsoft, among 17 vendor product lines we regularly install, configure, and support across networking, cybersecurity, CCTV, and cloud infrastructure — hands-on experience that informs the technical guidance in our articles.
Our work is independently rated 5.0 out of 5 from 17 verified Google Reviews. Every article is reviewed internally for technical accuracy before publishing and reflects practices we apply on real client deployments in Dubai and the UAE.
SAS IT Services — Dubai
Need expert IT support?
Our experienced engineers cover all of Dubai & UAE with same-day response and 24/7 support contracts.