Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
suthomas1
New Contributor

connections not working

Hello All, We have two connections ( src & port being the same for both ). However, one connection is working but the other is not working. I did some debugs ,but the non-working stops at finding a session. Below are the both the traces, appreciate if there can be any help on possible options to check for this. Thank you in advance. Non-working:- src: 192.168.100.254 dst: 172.16.10.50 id=36870 trace_id=1 msg=" vd-root received a packet(proto=6, 192.168.100.254:4359->172.16.10.50:3282) from port1." id=36870 trace_id=1 msg=" allocate a new session-0112d977" id=36870 trace_id=1 msg=" find a route: gw-172.16.10.50 via SR-MGMT" id=36870 trace_id=1 msg=" Allowed by Policy-16:" id=36870 trace_id=2 msg=" vd-root received a packet(proto=6, 192.168.100.254:4359->172.16.10.50:3282) from port1." id=36870 trace_id=2 msg=" Find an existing session, id-0112d977, original direction" Working:- src: 192.168.100.254 dst: 172.16.10.50 id=20085 trace_id=1 msg=" vd-root received a packet(proto=6, 192.168.100.254:4864->172.16.98.20:3282) from internal." id=20085 trace_id=1 msg=" allocate a new session-0500311b" id=20085 trace_id=1 msg=" find a route: gw-172.16.10.50 via SR-MGMT" id=20085 trace_id=1 msg=" Allowed by Policy-12:" id=20085 trace_id=2 msg=" vd-root received a packet(proto=6, 192.168.100.254:4864->172.16.10.50:3282) from internal." id=20085 trace_id=2 msg=" Find an existing session, id-0500311b, original direction" id=20085 trace_id=3 msg=" vd-root received a packet(proto=6, 192.168.100.254:4864->172.16.10.50:3282) from internal." id=20085 trace_id=3 msg=" Find an existing session, id-0500311b, original direction" id=20085 trace_id=4 msg=" vd-root received a packet(proto=6, 192.168.100.254:4864->172.16.10.50:3282) from internal." id=20085 trace_id=4 msg=" Find an existing session, id-0500311b, original direction" id=20085 trace_id=13 msg=" vd-root received a packet(proto=6, 10.199.2.38:389->172.16.10.50:36073) from internal." id=20085 trace_id=13 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=13 msg=" find a route: gw-172.16.10.50 via SR-MGMT" id=20085 trace_id=14 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal." id=20085 trace_id=14 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=15 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal." id=20085 trace_id=15 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=16 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal." id=20085 trace_id=16 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=17 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal." id=20085 trace_id=17 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=18 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal." id=20085 trace_id=18 msg=" Find an existing session, id-05003120, reply direction" id=20085 trace_id=19 msg=" vd-root received a packet(proto=6, 172.16.16.21:389->172.16.10.50:36073) from internal.
Suthomas
Suthomas
1 REPLY 1
emnoc
Esteemed Contributor III

Are the ports in service on that hosts? Did you perform any diagnostic sniffer diag sniffer packet any " port 3282" [/I} The diag debug flow shows valid fwpolicies that allow traffic. What i would do, 1: telnet from a local machine to the port #, make sure you get a SYN and SYN-ACK 2: diag sniffer the port while a remote uses { 192.168.100.254 or whatever it is ) is attempting access . Do you see the client SYN and the server SYN-ACK 3: ensure you have no weird inspection policies that could interfer

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors