Skip to Content

What to do when FortiManager is not reflecting policy hitcounts

This article describes what to do when FortiManager is not reflecting policy hitcounts.

Scope

All versions of FortiManager.

Solution

FortiGate is showing hitcounts for a firewall policy:

FortiGate is showing hitcounts for a firewall policy.

However, the hitcount is not synced with FortiManager even when it is refreshed:

UUID FMG

This is due to the difference in policy UUID between FortiGate and FortiManager:

UUID FGT 1

Policy UUID on FortiGate: 244e8db8-4287-51ef-72f7-a18c9292e0fc.

Policy UUID on FMG: 244e8db8-4287-51ef-72f7-a18c9292e0fd.

FortiManager maps policy-related information retrieved from FortiGate such as hitcount and bytes to policies with corresponding UUIDs. To make sure hitcount is synchronized, policy UUIDs must be synchronized as well by either installing them from FortiManager or importing them from FortiGate.

UUID install

UUID FGT 2