Well for starters you're looking in the wrong log. You want the "Forward traffic" log for traffic that the FortiGate forwards along the way. Local traffic is for traffic with the FortiGate itself as the destination.
Next, your concept of traffic is wrong. When you load a webpage most of the traffic is inbound, yes, but the request is initiated outbound which is what matters where firewalls are concerned. So if you were looking for SSH traffic you would look for traffic with port 22 as the destination port.
However, this is unlikely to help you much with Teams as much of it is regular old HTTPS traffic. Honestly I'm no expert as we've avoided using Teams in our environment, but you'll have better luck with application control than with simple port-based searches.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.