Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
s_rowe
New Contributor

dirty_handler / no matching session

Hey all, Getting an error from debug outbput: ...fw-dirty_handler..." no session matched" ... We have multiple clients sending the same type of traffic to a single public IP address using destination NAT using the interface IP (so 1 to 1 NAT). Works fine until there are multiple simultaneous sessions established. I thought there would be an easy answer but i cant find anything on those messages in either the kb or on the forum. Hopefully an easy answer/solution. Thanks, Shannon
3 REPLIES 3
romanr
Valued Contributor

Hi, what kind of traffic is this? Some traffic, which is free of port identifiers (like GRE or ESP) will always make troubles if you want to translate more then 1 ip on the inside to only one ip on the outside... br, Roman
s_rowe
New Contributor

Hi Roman, Thanks for your reply. It is eftpos / point of sale transaction traffic. TCP using the ephemeral ports. Not recognized by FortiOS as a " service" . Thanks, Shannon
romanr
Valued Contributor

Hi, NAT with TCP should normally not be a problem. Can you post a bit more details of how you configured your policies? Also some more detailed output to the traffic (like sniffer dump and " diag debug flow" output, when this is happening). If you connect your inside to one public ip - you would normally use source NAT and so either an ip pool or the firewalls ip. br, Roman
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors