Created on
12-16-2019
06:59 AM
Edited on
05-09-2025
01:43 AM
By
Jean-Philippe_P
Description
This article describes possible root causes of having logs with interface 'unknown-0'.
Scope
FortiGate.
Solution
There are several scenarios, which such a log message can be generated:
Below are two examples of such a scenario:
An example of such scenario can be a TCP session removed from the session table after 'session-ttl' value is expired for it.
In case the session is removed earlier than client closed it, such client may still try to use it.
As FortiGate will not expect to receive any TCP packets except TCP SYN triggering creation of a new session, all other packets will be dropped due to 'implicit deny' policy (ID 0) match and 'unknown-0' log message will be generated.
In such case, if for any reason client still sends packets related to the removed session, packets are dropped due to 'implicit deny' policy (ID 0) match and 'unknown-0' log message is generated.
In both examples, ‘No Session Match’ messages are seen in the debug flow logs.
Related article:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.