| Description | This article explains the meaning of the 'DP sess' packets observed on FortiGate chassis devices when running a sniffer capture. |
| Scope | FortiGate-6000/7000. |
| Solution |
When running a packet capture on the SLBC platform devices, the following output can be observed:
diagnose sniffer packet any 'host 192.168.20.1 and host 172.16.1.30' 4 0 l [FPC01] 2025-09-25 10:27:36.795595 port28 in 192.168.20.1 -> 172.16.1.30: icmp: echo request
The packets marked with '(DP Sess)' should not be considered duplicates. The SLBC distributed processor (DP) internally uses these packets to load balance traffic across Fabric Processor Cards (FPCs) or Fabric Processing Modules (FPMs). As a result, this is expected behavior. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.