Skip to main content
Fern-X
New Member
October 11, 2023
Question

What is device/interface index 0?

  • October 11, 2023
  • 5 replies
  • 2770 views

In session list below, I can see reference to device/interface index 0 (see "dev=0->0/0->0"), but "diagnose sys device list" does not show such. What is device/interface index 0?

 

 

# diagnose sys session list : session info: proto=17 proto_state=00 duration=134 expire=45 timeout=0 flags=00000000 socktype=0 sockport=0 av_idx=0 use=3 origin-shaper= reply-shaper= per_ip_shaper= class_id=0 ha_id=0 policy_dir=0 tunnel=/ vlan_cos=0/255 state=log dirty may_dirty npu f00 statistic(bytes/packets/allow_err): org=76/1/1 reply=0/0/0 tuples=2 tx speed(Bps/kbps): 0/0 rx speed(Bps/kbps): 0/0 orgin->sink: org pre->post, reply pre->post dev=0->0/0->0 gwy=0.0.0.0/0.0.0.0 hook=pre dir=org act=noop censored1:48499->censored2:123(0.0.0.0:0) hook=post dir=reply act=noop censored2:123->censored1:48499(0.0.0.0:0) misc=0 policy_id=18 auth_info=0 chk_client_info=0 vd=1 serial=e01d0871 tos=ff/ff app_list=0 app=0 url_cat=0 sdwan_mbr_seq=0 sdwan_service_id=0 rpdb_link_id=00000000 rpdb_svc_id=0 ngfwid=n/a npu_state=00000000 npu info: flag=0x00/0x00, offload=0/0, ips_offload=0/0, epid=0/0, ipid=0/0, vlan=0x0000/0x0000 vlifid=0/0, vtag_in=0x0000/0x0000 in_npu=0/0, out_npu=0/0, fwd_en=0/0, qid=0/0 no_ofld_reason :

 

 

5 replies

Toshi_Esumi
SuperUser
SuperUser
October 11, 2023

I would assume dev=0 means itself because my own 40F's NTP session (UDP(17) 123) is origined from dev=0. But I don't understand your case because the destination is also 0 and policy_id is 18. What's in policy#18?

 

Toshi

Fern-X
Fern-XAuthor
New Member
October 11, 2023

Hi Toshi, here:

 

config vdom

edit censored-vdom

config firewall policy

:

edit 18
set uuid censored
set srcintf "censored-zone"
set dstintf "censored-npu0_vlink1"
set srcaddr "censored-addgrp"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
next

:

Toshi_Esumi
SuperUser
SuperUser
October 11, 2023

I think it speaks itself.

Zones include multiple interfaces so can't set IDs. Packets to npu_vlinks are offloaded from CPU and managed by npu so probably don't need dev IDs.

 

<edit>also does this vdom happen to be in transparent mode? I didn't see any gateway info either.</edit>

 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!