Hi all,
With my fortiVM, i can see a lot of session clash, can you tell me what does this error mean?
Thank you in advance,
Are you seeing this from the diag cmd
e.g
diag sys session stat misc info: session_count=21849 setup_rate=99 exp_count=0 clash=889 memory_tension_drop=0 ephemeral=0/57344 removeable=0 ha_scan=0 delete=0, flush=0, dev_down=0/0 TCP sessions: 127 in ESTABLISHED state 30 in SYN_SENT state 1 in FIN_WAIT state 8 in TIME_WAIT state 2 in CLOSE state 4 in CLOSE_WAIT state firewall error stat: error1=00000000 error2=00000000 error3=00000000 error4=00000000 tt=00000000 cont=00000000 ids_recv=19209c98 url_recv=00000000 av_recv=00000077 fqdn_count=00000000 tcp reset stat: syncqf=1 acceptqf=0 no-listener=9282 data=0 ses=0 ips=0 global: ses_limit=0 ses6_limit=0 rt_limit=0 rt6_limit=0
This means you have ephemeral port exhausation. I would look at the following;
1: infection or malware/botagents/etc
2: session ttl
3: I would monitor the ephemeral counter very closely
PCNSE
NSE
StrongSwan
Hello emnoc and thank you for your help, here is the result of the diag command :
FGVM-ITX (global) # diag sys session stat
misc info: session_count=3257 setup_rate=154 exp_count=30 clash=69
memory_tension_drop=0 ephemeral=0/327680 removeable=0
delete=0, flush=0, dev_down=0/0
TCP sessions:
28 in NONE state
858 in ESTABLISHED state
37 in SYN_SENT state
2 in SYN_RECV state
1 in FIN_WAIT state
95 in TIME_WAIT state
73 in CLOSE state
23 in CLOSE_WAIT state
firewall error stat:
error1=00000000
error2=00000000
error3=00000000
error4=00000000
tt=00000000
cont=000bf364
ids_recv=02f802e3
url_recv=00000000
av_recv=0053144c
fqdn_count=00000001
tcp reset stat:
syncqf=406 acceptqf=0 no-listener=5245 data=0 ses=2 ips=0
global: ses_limit=0 ses6_limit=0 rt_limit=0 rt6_limit=0
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.