Skip to main content
jiwon_kang
New Member
July 21, 2020
Question

session clash log

  • July 21, 2020
  • 1 reply
  • 3607 views

hi, 

 

Please tell me why the log occurred and how to take action.

I am using forti-OS 5.6.8

 

07 | 20 | "0100020085" | session clash" new_status="state=00010404 tuple-num=2 policyid=107 identidx=0 dir=0 act=2 hook=0 1.226.64.90:43443->172.25.5.234:5911(218.146.32.6:10329)

dir=1 act=1 hook=4 218.146.32.6:10329->1.226.64.90:43443(172.25.5.234:5911)" old_status="state=00010404 tuple-num=2 policyid=107 identidx=0 dir=0 act=2 hook=0

1.226.64.90:43443->172.25.5.234:5909(218.146.32.6:10329) dir=1 act=1 hook=4 218.146.32.6:10329->1.226.64.90:43443(172.25.5.234:5909)

 

thanks

1 reply

Yurisk
SuperUser
SuperUser
July 21, 2020

"Session clash messages appear in the logs when a new session is created but a conflicting similar session already exists."  https://kb.fortinet.com/kb/documentLink.do?externalID=FD37215

Usually happens while doing NAT of some sort Fortigate runs out of the free/available ports to do the translation for the new arriving connection. 

yurisk.info - all things Fortinet blog, no ads
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.