Firewall Log Management · Panel › Firewall Rules

Firewall Rules: manage your firewall policies from the panel.

The Firewall Rules page reads your FortiGate and MikroTik firewalls' policies in the panel, lets you edit them, and shows hit counters and change history. On other drivers this page is marked "not supported."

  • Read + write: FortiGate and MikroTik
  • Auto-sync every 10 minutes + manual sync
  • Hit counters and field-level change history
Support
FortiGate + MikroTik
Other drivers
Not supported
Sync
10 min auto + manual
Hits
Firewall + izgate log
History
Who/when/which field
Write
Enable/disable/add/edit/delete
izgate Firewall Rules page: KPI cards, the rules table, hit counters, and the last sync time
Firewall Rules: KPI cards, the rules table, and hit counters
What's on the screen?

Sections of the Firewall Rules page

  1. Top bar: the "Firewall Rules" heading, a device selector (to switch between firewalls if you have more than one), "Import," "Export," and a "New Rule" button.
  2. KPI cards: total rule count, active rule count (with a percentage ring), disabled rule count, hits in the last 24 hours (orange sparkline), blocked hit count (purple sparkline), and a security indicator.
  3. Filter row: a rule name/description/source/destination search box; All Statuses, All Types, All Zones, All Services, All Users dropdowns, and "Clear Filters."
  4. Rules table header: "Rules (n)" and the last sync time; Sort, Columns, Bulk Actions, and a refresh button on the right.
  5. Table columns: a select checkbox, order number, status (enable/disable toggle), name, source, destination, service, zones, action, log, hit count (with a sparkline), and description.
  6. Rule Detail panel: opens from the right when you click a rule; General/Statistics/Logs/Change History tabs, General Information (name, description, status, UUID, last sync, last used, usage count), Rule Structure (source, destination, service, zones, action, log), and an "Edit" button.
What can you do?

Read, change, and prove your policies

Read + write

On FortiGate and MikroTik, rules can be enabled/disabled/added/edited/deleted. On other drivers, it's not just write access that's missing — the page itself isn't supported, and the panel shows "not supported."

Automatic + manual sync

Firewall policies are read automatically every 10 minutes; use the "Sync" button to update them manually at any time.

Two-source hit counter

The firewall's own hit counters are shown side by side with the log hits izgate has collected, so you can see at a glance how much traffic a rule is actually matching.

Change history

Every rule change is recorded with who made it, when, and which field changed. Review it retrospectively from the "Change History" tab in the Rule Detail panel.

Rule Detail and Statistics

Clicking a rule shows its UUID, last sync/used time, and usage count along with its source/destination/service/zone/action/log structure; the "Statistics" and "Logs" tabs give a deeper view of the rule's traffic.

izgate Rule Detail panel: general information, rule structure, and an edit button
Rule Detail: general information, rule structure, change history tab
Rule Detail

A rule's entire history, in one panel

Clicking a rule in the table opens a panel on the right that lists the rule's name, description, status, unique identifier (UUID), last sync and last used time, and usage count under "General Information." The "Rule Structure" section shows the source, destination, service, zones, action, and log setting; the "Edit" button at the top right lets you change these fields.

How to use it

Three steps to review a rule

1

Pick the device

Choose your FortiGate or MikroTik device from the device selector in the top bar.

2

Filter and review

Find the relevant rule with the filters; gauge the overall picture with hit counts and the KPI cards.

3

Edit or sync

Edit from the Rule Detail panel, or pull the current state straight from the firewall with "Sync"; it's automatically recorded in the change history.

Good to know

Limits, stated plainly

The Firewall Rules page only works on FortiGate and MikroTik. On Sophos, Palo Alto, pfSense, OPNsense, and generic syslog drivers, the page shows "not supported" — there isn't even a read-only view for these drivers. Sophos and Palo Alto adapters are on the roadmap.
There's no country-based hit enrichment on this page; hit counters come from the firewall's own counters matched against izgate's logs.
Frequently asked questions

About the Firewall Rules page

Which firewalls does the Firewall Rules page work with?

Only FortiGate and MikroTik; on these two drivers policies can be read, edited, enabled/disabled, added, and deleted. The page isn't supported on other drivers.

How often are rules synced?

Automatically every 10 minutes; you can also sync manually at any time with the "Sync" button.

Where does the hit count come from?

From two sources: the firewall's own hit counters and matches in the logs izgate has collected; both are shown together.

Can I see who changed a rule, and when?

Yes, the Change History tab in the Rule Detail panel lists who changed which field, and when.

What happens if I open the Firewall Rules page on an unsupported device?

The panel shows the page as "not supported"; there isn't a read-only view either for these drivers.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.