Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
greminn
New Contributor III

Files were dropped by quard to xfer-fas: 0 reached max retries, 1 reached TTL.

Hi There, Im using one of our (now) redundant 80C's on my home fibre connection. We are using 5.2.1. and it is connected to a IPS-supplied fibre ONT. We have had a couple of outages lately... and seeing this in the logs. This appears when we are experiencing the outage.

 

1 files were dropped by quard to xfer-fas: 0 reached max retries, 1 reached TTL.

2 files were dropped by quard to xfer-fas: 0 reached max retries, 2 reached TTL.

2 files were dropped by quard to xfer-fas: 0 reached max retries, 2 reached TTL.

2 files were dropped by quard to xfer-fas: 0 reached max retries, 2 reached TTL. And so on (kind of every 10 mins during the outage)

 

Looking the details of the message, it lists the Reason as: poor-network-condition - From this im thinking that it is something todo with the fibre ONT. Anyh thoughts? 

 

Any info is much appreciated! :) I have attached a screenshot for reference.

 

BTW: What a great error message! I would hate to be dropped by anything called a quard 

1 REPLY 1
Jeff_FTNT
Staff
Staff

You may enable "log to FortiAnalyzer" and send AV quarantine/IPS packet Log/DLP archive file to FortiAnalyzer.

For some reason, FortiAnalyzer can not handle those request or FGT is too busy to handle (like memory is high), FGT will fail to transfer AV quarantine/IPS packet Log/DLP archive filen to FortiAnalyzer.

 

Hope it will be helpful, thanks.

Labels
Top Kudoed Authors