Created on
06-20-2024
11:14 PM
Edited on
06-20-2024
11:15 PM
By
Anthony_E
Description |
This article describes how to fix the error 'Session is in BLOCK state. Drop the packet'.
|
Scope | FortiGate. |
Solution |
By default, the service 'ALL' is set to use protocol type 'IP', with protocol number 0 meaning any.
However, if the protocol type is set to TCP/UDP/SCTP and the source and destination ports are set to 0, it means that it is blocked all or (any to null) and tagged as in BLOCK state by the firewall policy.
To fix this error, verify that the correct port or port range is in use. If setting the TCP/UDP/SCTP port to 0, it means that it will never match any traffic and will give an error message of 'Session is in BLOCK state. Drop the packet'.This is applicable to any custom service. |