FortiGate Policy X-Ray overview
FortiGate Policy X-Ray turns the latest saved firewall configuration into four operator views: policy inspection, hygiene and cleanup, traffic simulation, and drift history. It is read-only. Nothing you do in Policy X-Ray changes the FortiGate.
The page header reads Policy Optimization & Cleanup, with the subtitle Rule hygiene · object cleanup · L7 pipeline analysis.

Before you start
- Connect and scan at least one FortiGate device. See the SCM FortiGate dashboard and agent guides for Windows or Docker.
- Make sure your role can view FortiGate findings. The permission is under Settings > Roles & Permissions, in the FortiGate group.
- Use a plan that includes SCM. See the plan feature matrix.
Select a device
Use the device selector in the header to change firewalls. A device on its first scan shows Baseline because no earlier snapshot exists for drift comparison.
The Last scan indicator describes snapshot age:
- Grey: captured within the last seven days.
- Amber: more than seven days old.
- Red: more than 30 days old.
Hover the indicator for the exact capture time. Run a fresh scan before a production decision when the snapshot is stale.
The four tabs
| Tab | Use it to |
|---|---|
| X-Ray Analysis | Review each policy's inspection pipeline, Domino Effect, risk score, and prioritized fixes. See The Domino Effect. |
| Hygiene & Cleanup | Find stale, unused, expired, and provable cross-policy anomalies; then review unused and duplicate objects. See Hygiene & Cleanup. |
| Simulator | Estimate which saved policy would handle a specific IPv4 flow and trace ingress, policy lookup, profiles, NAT, egress, and decision. See Policy Simulator. |
| Drift History | Compare snapshots and review added, removed, and modified configuration. See Drift History. |
Recommendations and exports
Recommendations opens Top fixes for this device, a prioritized list across the selected firewall. Each item includes severity, source, affected policies, and a copyable configuration fix where Retrievy can provide one safely.
The export menu includes Policy inventory CSV, FortiGate evidence PDF, and Schedule delivery. Export and scheduling availability depends on your plan and report permissions.
Snapshot limits
Policy X-Ray analyzes the latest collected configuration and stored telemetry. It does not inspect live sessions or query the management plane while you browse. A configuration change made after the scan will not appear until the next collection.
The simulator and anomaly engine intentionally avoid claims when configuration alone cannot prove a result. Dynamic routing, SD-WAN decisions, identity, dynamic address sources, and translation features can reduce confidence or prevent evaluation. Review the limits on Policy Simulator and Hygiene & Cleanup.
How this affects your Retrievy Index
FortiGate policy and Layer-7 detections with Critical, High, Medium, or Low severity feed SCM FortiGate Policies, which uses a per-module sensitivity of 4.0. Examples include unrestricted allow rules, overly broad services, traffic logging gaps, unreachable shadowed rules, unrestricted WAN management, expired temporary rules, and inspection-control gaps.
Telemetry cleanup observations such as stale rules, zero-hit rules, and empty objects can be tracked as informational findings. Informational findings carry zero weight. Drift events, simulator results, and asset tags do not directly change the Index.
See the scoring rules catalog for current scoring inputs and weights.
Troubleshooting
Policy X-Ray shows Zero Data. Run a new scan. The workspace needs a parsed configuration snapshot, which may not exist even when older findings are visible.
A completed scan is not visible yet. Policy X-Ray shows a completion message but does not replace the open view automatically. Reload the page to load the new snapshot.
The device is marked Baseline. Complete another scan after a change to begin drift comparison.