FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Nik_Aiman
Staff
Staff
Article Id 310468
Description This article describes that if the VIP is a member of a VIPGRP, the GUI will not show the hit count on the VIP list.
Scope FortiGate.
Solution

When the configured VIP security policy contains a VIP Group object, the VIP object's hit count will show 0 even though there is a hit count in the firewall policy.

 

Firewall Policy with VIP group address:

 

Picture1.png

 

VIP Object ‘hit count’ is 0:

 

Picture2.png

 

It is an expected behavior.

 

Alternatively, the hit count can be retrieved using the CLI via the below command:

 

diagnose firewall iprope show 100000 <VIP ID>

 

Example:

 

diagnose firewall iprope show 100000 1

idx=1

hit count:13 (9 0 0 4 0 0 0 0)

    first hit:2024-04-01 12:17:34 last hit:2024-04-19 14:38:21

 

Workaround:

  1. Use the VIP object in the firewall policy instead of the VIP group:

 

Picture3.png

 

  1. Once the traffic hits the policy which uses the VIP object, the hit count will be increase:

 

Picture5.png

Contributors