| Description | This article describes the case when users find a deny traffic log with the message 'replay packet(allow_err), suspicious'. |
| Scope | FortiGate, all versions. |
| Solution |
Below is shown how to check the root cause of the traffic log 'replay packet(allow_err), suspicious'.
If a user gets the log message 'replay packet(allow_err), suspicious', it is possible to run the flow debug to see more details. Below is an example of duplicate traffic and it is denied.
id=20095 trace_id=4028 func=print_pkt_detail line=5918 msg="vd-Test:0 received a packet(proto=6, 192.168.1.2:57220->172.16.1.2:514) tun_id=0.0.0.0 from port1. flag [R], seq 1145693491, ack 1145693491, win 0"
id=20095 trace_id=4029 func=print_pkt_detail line=5918 msg="vd-Test:0 received a packet(proto=6, 192.168.1.2:57220->172.16.1.2:514) tun_id=0.0.0.0 from port1. flag [R], seq 1145693492, ack 1145693492, win 0" |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.