Skip to main content

FortiGate Policy X-Ray overview

FortiGate Policy X-Ray turns the latest saved firewall configuration into four operator views: policy inspection, hygiene and cleanup, traffic simulation, and drift history. It is read-only. Nothing you do in Policy X-Ray changes the FortiGate.

The page header reads Policy Optimization & Cleanup, with the subtitle Rule hygiene · object cleanup · L7 pipeline analysis.

Policy X-Ray header focused on the workspace title and four analysis tabs

Before you start

  • Connect and scan at least one FortiGate device. See the SCM FortiGate dashboard and agent guides for Windows or Docker.
  • Make sure your role can view FortiGate findings. The permission is under Settings > Roles & Permissions, in the FortiGate group.
  • Use a plan that includes SCM. See the plan feature matrix.

Select a device

Use the device selector in the header to change firewalls. A device on its first scan shows Baseline because no earlier snapshot exists for drift comparison.

The Last scan indicator describes snapshot age:

  • Grey: captured within the last seven days.
  • Amber: more than seven days old.
  • Red: more than 30 days old.

Hover the indicator for the exact capture time. Run a fresh scan before a production decision when the snapshot is stale.

The four tabs

TabUse it to
X-Ray AnalysisReview each policy's inspection pipeline, Domino Effect, risk score, and prioritized fixes. See The Domino Effect.
Hygiene & CleanupFind stale, unused, expired, and provable cross-policy anomalies; then review unused and duplicate objects. See Hygiene & Cleanup.
SimulatorEstimate which saved policy would handle a specific IPv4 flow and trace ingress, policy lookup, profiles, NAT, egress, and decision. See Policy Simulator.
Drift HistoryCompare snapshots and review added, removed, and modified configuration. See Drift History.

Recommendations and exports

Recommendations opens Top fixes for this device, a prioritized list across the selected firewall. Each item includes severity, source, affected policies, and a copyable configuration fix where Retrievy can provide one safely.

The export menu includes Policy inventory CSV, FortiGate evidence PDF, and Schedule delivery. Export and scheduling availability depends on your plan and report permissions.

Snapshot limits

Policy X-Ray analyzes the latest collected configuration and stored telemetry. It does not inspect live sessions or query the management plane while you browse. A configuration change made after the scan will not appear until the next collection.

The simulator and anomaly engine intentionally avoid claims when configuration alone cannot prove a result. Dynamic routing, SD-WAN decisions, identity, dynamic address sources, and translation features can reduce confidence or prevent evaluation. Review the limits on Policy Simulator and Hygiene & Cleanup.

How this affects your Retrievy Index

FortiGate policy and Layer-7 detections with Critical, High, Medium, or Low severity feed SCM FortiGate Policies, which uses a per-module sensitivity of 4.0. Examples include unrestricted allow rules, overly broad services, traffic logging gaps, unreachable shadowed rules, unrestricted WAN management, expired temporary rules, and inspection-control gaps.

Telemetry cleanup observations such as stale rules, zero-hit rules, and empty objects can be tracked as informational findings. Informational findings carry zero weight. Drift events, simulator results, and asset tags do not directly change the Index.

See the scoring rules catalog for current scoring inputs and weights.

Troubleshooting

Policy X-Ray shows Zero Data. Run a new scan. The workspace needs a parsed configuration snapshot, which may not exist even when older findings are visible.

A completed scan is not visible yet. Policy X-Ray shows a completion message but does not replace the open view automatically. Reload the page to load the new snapshot.

The device is marked Baseline. Complete another scan after a change to begin drift comparison.