Skip to main content
SoulFlazer
New Member
May 28, 2019
Question

Fortigate log in FortiAnalyzer - Intermittent deny log with dst interface "unknown-0"

  • May 28, 2019
  • 0 replies
  • 2283 views
Hi,

 

Today in the fortianalyzer with firmware 5.6.6 connected to a FortiGate cluster of 3000D with firmware 5.6.6 we noticed some logs related to TCP sessions that intermittently are displayed as deny-policy violation - destination interface "unknown-0".

 

For that particular type of flow there is a configured policy that is matched and the logs shown on the fortinanalyzer alternate with the policy permit and the deny policy violation log ID: dst "unknown-0" - Log ID 0000000007.

 

Someone has had occasion to clash with this problem? could it be related to some timer value on TCP sessions since intermittent logs come only on logs belonging to TCP sessions?

 

Thanks in advance for the support!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!