Skip to main content
limvuihan
New Member
December 11, 2017
Question

After enable WCCP on policy the traffic hit another rules

  • December 11, 2017
  • 7 replies
  • 8553 views

After enable WCCP the output changed

 

Any reason the session by not hitting the rule

 

herewith the diagnostic output

id=20085 trace_id=533 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.32.45.254 via dmz"

id=20085 trace_id=533 func=fw_forward_handler line=686 msg="Allowed by Policy-2: SNAT" id=20085 trace_id=533 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=534 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [.], seq 290866627, ack 926030060, win 16567" id=20085 trace_id=534 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=534 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=535 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=535 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=535 func=fw_forward_dirty_handler line=354 msg="blocked by forwarding policy (internal1->dmz), drop" id=20085 trace_id=535 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=536 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=536 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=536 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=537 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=537 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=537 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=538 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=538 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=538 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=539 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=539 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=539 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=540 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [F.], seq 290870012, ack 926035147, win 16695" id=20085 trace_id=540 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=540 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=541 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58861->1.1.1.1:443) from internal1. flag [R.], seq 290870013, ack 926035147, win 0" id=20085 trace_id=541 func=resolve_ip_tuple_fast line=4541 msg="Find an existing session, id-00009b24, original direction" id=20085 trace_id=541 func=__ip_session_run_tuple line=2597 msg="SNAT 10.10.10.1->10.32.45.50:58861" id=20085 trace_id=542 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:58892->1.1.1.1:443) from internal1. flag , seq 134236980, ack 0, win 8192" id=20085 trace_id=542 func=init_ip_session_common line=4631 msg="allocate a new session-00009b84" id=20085 trace_id=542 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.32.45.254 via dmz" id=20085 trace_id=542 func=fw_forward_handler line=561 msg="Denied by forward policy check (policy 0)"

 

 

 

    7 replies

    emnoc
    New Member
    December 11, 2017

    Okay what does fwpolicyid2 have? What do you have for WCCP ?

     

    limvuihan
    limvuihanAuthor
    New Member
    December 11, 2017

    policy 2 is permit ip any any

     

    WCCP

    - L2 WCCP

    - perform diag wccp with positive result

    - cache server wccp status is ready

     

    Config

    config system wccp

    edit "90" set router-id 10.10.10.254 set group-address 0.0.0.0 set server-list 10.10.10.212 255.255.255.255 set authentication disable set forward-method L2 set return-method L2 set assignment-method HASH next end

     

    Interface also done wccp enable

     

    limvuihan
    limvuihanAuthor
    New Member
    December 13, 2017

    Hi All,

     

    Debug log

    before

    id=20085 trace_id=2077 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:50315->157.240.10.35:443) from internal1. flag , seq 2021934820, ack 0, win 8192" id=20085 trace_id=2077 func=init_ip_session_common line=4631 msg="allocate a new session-000fd017" id=20085 trace_id=2077 func=iprope_dnat_check line=4633 msg="in-[internal1], out-[]" id=20085 trace_id=2077 func=iprope_dnat_check line=4646 msg="result: skb_flags-00800000, vid-0, ret-no-match, act-accept, flag-00000000" id=20085 trace_id=2077 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.10.10.254 via wan1" id=20085 trace_id=2077 func=iprope_fwd_check line=630 msg="in-[internal1], out-[wan1], skb_flags-00800000, vid-0" id=20085 trace_id=2077 func=__iprope_tree_check line=543 msg="gnum-100004, use addr/intf hash, len=4" id=20085 trace_id=2077 func=__iprope_check_one_policy line=1833 msg="checked gnum-100004 policy-1, ret-no-match, act-accept" id=20085 trace_id=2077 func=__iprope_check_one_policy line=1833 msg="checked gnum-100004 policy-10, ret-matched, act-accept" id=20085 trace_id=2077 func=__iprope_user_identity_check line=1668 msg="ret-matched" id=20085 trace_id=2077 func=__iprope_check line=2043 msg="gnum-4e20, check-f8afca50" id=20085 trace_id=2077 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2077 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2077 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2077 func=__iprope_check line=2062 msg="gnum-4e20 check result: ret-no-match, act-accept, flag-00000000, flag2-00000000" id=20085 trace_id=2077 func=get_new_addr line=2759 msg="find SNAT: IP-10.10.10.254(from IPPOOL), port-50315" id=20085 trace_id=2077 func=__iprope_check_one_policy line=2014 msg="policy-10 is matched, act-accept" id=20085 trace_id=2077 func=iprope_fwd_auth_check line=682 msg="after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-10" id=20085 trace_id=2077 func=iprope_reverse_dnat_check line=800 msg="in-[internal1], out-[wan1], skb_flags-00800000, vid-0" id=20085 trace_id=2077 func=fw_forward_handler line=686 msg="Allowed by Policy-10: SNAT"

     

     

    Enable WCCP on policy 10

    FGT60D# config firewall policy 10 FGT60D(policy) # edit 10 FGT60D(10) # set wccp enable FGT60D(10) # end

     

     

    Diag debug show hit policy 11

    id=20085 trace_id=2099 func=print_pkt_detail line=4478 msg="vd-root received a packet(proto=6, 10.10.10.1:50331->157.240.10.35:443) from internal1. flag , seq 3202453016, ack 0, win 8192" id=20085 trace_id=2099 func=init_ip_session_common line=4631 msg="allocate a new session-000fd0ce" id=20085 trace_id=2099 func=iprope_dnat_check line=4633 msg="in-[internal1], out-[]" id=20085 trace_id=2099 func=iprope_dnat_check line=4646 msg="result: skb_flags-00800000, vid-0, ret-no-match, act-accept, flag-00000000" id=20085 trace_id=2099 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.10.10.254 via wan1" id=20085 trace_id=2099 func=iprope_fwd_check line=630 msg="in-[internal1], out-[wan1], skb_flags-00800000, vid-0" id=20085 trace_id=2099 func=__iprope_tree_check line=543 msg="gnum-100004, use addr/intf hash, len=4" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833 msg="checked gnum-100004 policy-1, ret-no-match, act-accept" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833 msg="checked gnum-100004 policy-10, ret-no-match, act-accept" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833a msg="checked gnum-100004 policy-11, ret-matched, act-accept" id=20085 trace_id=2099 func=__iprope_user_identity_check line=1668 msg="ret-matched" id=20085 trace_id=2099 func=__iprope_check line=2043 msg="gnum-4e20, check-f8afca50" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2099 func=__iprope_check_one_policy line=1833 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" id=20085 trace_id=2099 func=__iprope_check line=2062 msg="gnum-4e20 check result: ret-no-match, act-accept, flag-00000000, flag2-00000000" id=20085 trace_id=2099 func=get_new_addr line=2759 msg="find SNAT: IP-10.10.10.254(from IPPOOL), port-50331" id=20085 trace_id=2099 func=__iprope_check_one_policy line=2014 msg="policy-11 is matched, act-accept" id=20085 trace_id=2099 func=iprope_fwd_auth_check line=682 msg="after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-11" id=20085 trace_id=2099 func=iprope_reverse_dnat_check line=800 msg="in-[internal1], out-[wan1], skb_flags-00800000, vid-0" id=20085 trace_id=2099 func=fw_forward_handler line=686 msg="Allowed by Policy-11: SNAT"

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!