Technical Tip: ICMP error message processing on chassis based FortiGate
| Description | This article describes how the ICMP error messages are received on a chassis-based FortiGate. |
| Scope | FortiGate-6000F, 7000E and 7000F series. |
| Solution | Prerequisites:
Considering the following scenario:
Legit traffic [FPC01] 103.061234 v140 in 70.70.70.70.12345 -> 131.0.1.11.443: syn 987654 [FPC01] 103.061583 v141 out 141.0.1.106.12345 -> 131.0.1.11.443: syn 987654 [FPC01] 103.061586 port15 out 141.0.1.106.12345 -> 131.0.1.11.443: syn 987654
ICMP error message as a reply [FPC01] 103.062428 port15 out 141.0.1.254 -> 70.70.70.70: icmp: 131.0.1.11 unreachable - need to frag (mtu 800) [MBD ] 103.056377 v141 in 141.0.1.254 -> 141.0.1.106: icmp: 131.0.1.11 unreachable - need to frag (mtu 800)
Reply broadcasted |
