Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cheaman
New Contributor II

Policy 0

I' m seeing a fair amount of " Policy 0" with " No Session Matched" in our logs. Some of them are legit blocks, but a lot of them should match a policy and be allowed. What would cause this sort of deny?
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
22 REPLIES 22
ede_pfau
SuperUser
SuperUser

" policy 0" is the implicit DENY policy at the very bottom of the policy chain. Packets arriving here have not been matched by any (custom) policy. If you expect some traffic to match and leave through some other policy then you' ve got to debug the mismatch.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
cheaman
New Contributor II

Thanks Ede, I' ve put in a support ticket as it is happening across several policies that should be matching. It' s quite random, so I' m not quite sure how to debug it.
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
ede_pfau
SuperUser
SuperUser

Can you give an example?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
cheaman
New Contributor II

Here' s an example that should have matched a rule from 10.44.x.x to All 0.0.0.0 for HTTP. I' ve removed some of the irrelevant info: Status deny Src 10.44.2.251 Dst 65.55.227.140 Sent 0 B Received 0 B Rule 0 Service HTTP Policy ID 0 Level warning VDom root Serial Number 0 Duration 157451 Subtype other Type traffic Protocol 6 Log ID 7 Src Name 10.44.2.251 Dst Name 65.55.227.140 Src Interface port5 Dst Interface N/A Src Port 63265 Dst Port 80 Shaper Dropped Sent Bytes 0 Shaper Dropped Received Bytes 0 Per-IP Shaper Bytes Dropped 0 Destination Country United States Message no session matched
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
rwpatterson
Valued Contributor III

Let' s see the policy that should have matched.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
cheaman
New Contributor II

Here' s a snippet from a flow trace. This should have matched the same rule as above but for HTTPS: id=36871 trace_id=494 msg=" vd-root received a packet(proto=6, 10.44.2.7:55932->193.149.73.30:443) from port5." id=36871 trace_id=494 msg=" find a route: gw-(our gateway IP) via port1" id=36871 trace_id=494 msg=" no session matched" removed our gateway IP.
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
emnoc
Esteemed Contributor III

Here' s an example that should have matched a rule from 10.44.x.x to All 0.0.0.0 for HTTP. I' ve removed some of the irrelevant info: Status deny Src 10.44.2.251 Dst 65.55.227.140
Will I see a specific host for the dst (65.55.227.140 ), 0.0.0.0 is any and 65.55.227.140 is a specific match. What' s the ordering of the fwpolicies? I would double check your fwpolicies and ordering and re-sequence.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
cheaman
New Contributor II

Here' s the relevant bits. The " Network - VM" = 10.44.0.0/16 set srcintf " port5" set dstintf " port1" set srcaddr " Network - VM" set dstaddr " All" set action accept set fsso enable set identity-based enable set nat enable set ippool enable set poolname " VM" config identity-based-policy edit 1 set schedule " always" set utm-status enable set groups " VM - All Users Fortigate" set service " ANY" set av-profile " Schools AntiVirus" set webfilter-profile " Schools Web Filter" set spamfilter-profile " Schools Email Filter" set application-list " Schools App Control" set profile-protocol-options " Schools"
Fortigate 1240B FAZ 4000A
Fortigate 1240B FAZ 4000A
ede_pfau
SuperUser
SuperUser

set identity-based enable
What will the firewall do with traffic if the user didn' t authenticate first - forward it?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors