Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MarcusH
New Contributor

Traffic Filter logical operations on ranges/subnets

Hi, we are using a Fortigate 6.4.6 with local logging. We would like to filter forward traffic log (and others) by negating or logically combining subnets or ranges.

Simple example: Destination NOT 95.96.0.0/16.

Slightly more complex example: Destination NOT (192.168.0.0/16 or 10.0.0.0/8 or 172.16.0.0/12).

Entering subnets converts the network to a range, but after that it is not possible to logically combine multiple ranges using OR or NOT.

Any solution on this?

Thank you

Marcus

1 REPLY 1
kgeorge
Staff
Staff

Hello Marcus,

 

Sorry that, this post was unaddressed so far.

 

Like to inform you that, we can use multiple individual entries for Destination Not however cannot combine it under one filter entry. 

"And" and "Or" are two separate values hence, using "Or" with "Not" filter will not work.

 

Regards,

Klint George

Regards,
Klint George
Labels
Top Kudoed Authors