Baddi_Aw # 2024-08-31 10:17:53 id=65308 trace_id=8 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.1
38.59:39491->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [S], seq 1152205440, ack 0, win 29200"
2024-08-31 10:17:53 id=65308 trace_id=8 func=init_ip_session_common line=6020 msg="allocate a new session-3e06eec6"
2024-08-31 10:17:53 id=65308 trace_id=8 func=vf_ip_route_input_common line=2612 msg="find a route: flag=00000000 gw-223.30.9.17 via p
ort3"
2024-08-31 10:17:53 id=65308 trace_id=8 func=__iprope_tree_check line=539 msg="gnum-100004, use addr/intf hash, len=55"
2024-08-31 10:17:53 id=65308 trace_id=8 func=get_new_addr line=1258 msg="find SNAT: IP-223.30.9.18(from IPPOOL), port-39491"
2024-08-31 10:17:53 id=65308 trace_id=8 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=9 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:39491
->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 1152205441, ack 2227930738, win 229"
2024-08-31 10:17:53 id=65308 trace_id=9 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original dir
ection"
2024-08-31 10:17:53 id=65308 trace_id=9 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 to
port3, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=9 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=000010
00"
2024-08-31 10:17:53 id=65308 trace_id=9 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=10 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
1->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 1152205441, ack 2227930738, win 229"
2024-08-31 10:17:53 id=65308 trace_id=10 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original di
rection"
2024-08-31 10:17:53 id=65308 trace_id=10 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port3, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=10 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:53 id=65308 trace_id=10 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=11 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
1->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 1152205643, ack 2227933127, win 266"
2024-08-31 10:17:53 id=65308 trace_id=11 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original di
rection"
2024-08-31 10:17:53 id=65308 trace_id=11 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port3, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=11 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:53 id=65308 trace_id=11 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=12 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
1->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 1152205643, ack 2227933127, win 266"
2024-08-31 10:17:53 id=65308 trace_id=12 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original di
rection"
2024-08-31 10:17:53 id=65308 trace_id=12 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port3, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=12 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:53 id=65308 trace_id=12 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=13 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
1->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [F.], seq 1152205650, ack 2227933127, win 266"
2024-08-31 10:17:53 id=65308 trace_id=13 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original di
rection"
2024-08-31 10:17:53 id=65308 trace_id=13 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port3, skb.npu_flag=00000000 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=13 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:53 id=65308 trace_id=13 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:53 id=65308 trace_id=14 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
1->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 1152205651, ack 2227933128, win 266"
2024-08-31 10:17:53 id=65308 trace_id=14 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06eec6, original di
rection"
2024-08-31 10:17:53 id=65308 trace_id=14 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port3, skb.npu_flag=00000000 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:53 id=65308 trace_id=14 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:53 id=65308 trace_id=14 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=15 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [S], seq 4157152624, ack 0, win 29200"
2024-08-31 10:17:54 id=65308 trace_id=15 func=init_ip_session_common line=6020 msg="allocate a new session-3e06f0aa"
2024-08-31 10:17:54 id=65308 trace_id=15 func=vf_ip_route_input_common line=2612 msg="find a route: flag=00000000 gw-45.248.156.89 vi
a port5"
2024-08-31 10:17:54 id=65308 trace_id=15 func=__iprope_tree_check line=539 msg="gnum-100004, use addr/intf hash, len=55"
2024-08-31 10:17:54 id=65308 trace_id=15 func=get_new_addr line=1258 msg="find SNAT: IP-45.248.156.90(from IPPOOL), port-39493"
2024-08-31 10:17:54 id=65308 trace_id=15 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=16 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 4157152625, ack 68456079, win 229"
2024-08-31 10:17:54 id=65308 trace_id=16 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06f0aa, original di
rection"
2024-08-31 10:17:54 id=65308 trace_id=16 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port5, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:54 id=65308 trace_id=16 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:54 id=65308 trace_id=16 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=17 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 4157152625, ack 68456079, win 229"
2024-08-31 10:17:54 id=65308 trace_id=17 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06f0aa, original di
rection"
2024-08-31 10:17:54 id=65308 trace_id=17 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port5, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:54 id=65308 trace_id=17 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:54 id=65308 trace_id=17 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=18 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 4157152827, ack 68458468, win 266"
2024-08-31 10:17:54 id=65308 trace_id=18 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06f0aa, original di
rection"
2024-08-31 10:17:54 id=65308 trace_id=18 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port5, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:54 id=65308 trace_id=18 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
2024-08-31 10:17:54 id=65308 trace_id=18 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=19 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [.], seq 4157152827, ack 68458468, win 266"
2024-08-31 10:17:54 id=65308 trace_id=19 func=resolve_ip_tuple_fast line=5924 msg="Find an existing session, id-3e06f0aa, original di
rection"
2024-08-31 10:17:54 id=65308 trace_id=19 func=npu_handle_session44 line=1213 msg="Trying to offloading session from PORT-CHANNEL251 t
o port5, skb.npu_flag=00000400 ses.state=04010b06 ses.npu_state=0x00001000"
2024-08-31 10:17:54 id=65308 trace_id=19 func=fw_forward_dirty_handler line=447 msg="state=04010b06, state2=00000001, npu_state=00001
000"
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Can you explain what is the issue in few words?
Thank you !!
Traffic is outputting port3 when the session is first opened, then it goes back to port5. I think there are 2 WANs. Port3 and Port5
My recommendation is to set the ECMP balance as source-destination.
65308 While on port3, the session suddenly goes to port5.
2024-08-31 10:17:53 id=65308 trace_id=14 func=av_receive line=480 msg="send to application layer"
2024-08-31 10:17:54 id=65308 trace_id=15 func=print_pkt_detail line=5836 msg="vd-root:0 received a packet(proto=6, 172.27.138.59:3949
3->20.190.145.140:443) tun_id=0.0.0.0 from PORT-CHANNEL251. flag [S], seq 4157152624, ack 0, win 29200"
2024-08-31 10:17:54 id=65308 trace_id=15 func=init_ip_session_common line=6020 msg="allocate a new session-3e06f0aa"
2024-08-31 10:17:54 id=65308 trace_id=15 func=vf_ip_route_input_common line=2612 msg="find a route: flag=00000000 gw-45.248.156.89 vi
a port5"
Hello @NeerajSofat1 ,
Thank you for contacting the Fortinet Forum portal.
Can you please provide details of what the issue is and your end goal trying to achieve?
Best regards,
Manasa.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.