FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kyozloveyou_FTNT
Article Id 334965
Description This article describes the function of the exceptional table and how to check the counters.
Scope FortiGate with Hyperscale enabled.
Solution

In the hyperscale environment, there is an exceptional table. The exceptional table shows the count of exceptional packets. The exceptional packet refers to ICMP unreachable, MTU too large (fragmentation required) messages, and other types of packets across the ICMP, TCP, and UDP protocols.

 

The exceptional table can be checked by running the following command:

 

HOSTNAME (global) # fnsysctl cat /proc/net/np7/excp
SSE_TTLCHKF (4 ):5513
SSE_FRAGPKT (6 ):108
IHP_L4CHKFAIL (22 ):182
IHP_L4APSFAIL (25 ):11673
PLE_NOT_SYN (72 ):7833870
L2P_FRAG_EXCP (80 ):589841
L2P_SSE_INFO_FAIL (82 ):140367
icmp_err_handle_nr:1301097
icmp_err_sess_search_nr:1114049
icmp_err_sess_cb_nr:1114049
icmp_err_sess_miss_nr:244502
icmp_err_sent_nr:1033041
icmp_err_fast_nr:60796
icmp_err_pkt_drop_nr:268056
large_pkt_count_nr:17
large_pkt_sess_search_nr:17
large_pkt_sess_cb_nr:17
large_pkt_processed_nr:17
frag_pkt_count_nr:589841
frag_pkt_process_nr:301721
frag_pkt_xmit_nr:288103
ttl_check_fail_handle_nr:5513
sess-stats: 3168/429598

 

Note: The counters will keep increasing until the FortiGate reboots.