Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JPM
New Contributor

" no session matched" message

Hi, I am hoping someone can help me. We get a " no session matched" (log_id=0038000007) message several thousand times a day for various different connections on our Fortigate 310B (4.0 MR3 patch 9) I believe this is caused by the anti replay setting which we could disable but I wanted to ask if it is safe to disable this setting or if there is some other setting which could be causing this message to be logged so many times per day. We also receive the message " replay packet(allow_err), drop" (log_id=0038000007) several thousand times a day which appears to be related to the same issue. If anyone can help with this I would appreciate it. Regards, JP
13 REPLIES 13
JPM
New Contributor

I have since noticed that the traffic appears to be sent to ips but the rule which allows this traffic does not have any ips sensors enabled, could this be the issue? id=36871 trace_id=8714 msg=" send to ips"
JPM
New Contributor

Is it safe to turn this option off? What are the consequences?
netmin
Contributor II

So...have you checked if the server/application on the mentioned IP logs any errors? The trace looks like the connections continue sending data bidirectionally without a valid session. If no errors are reported (and no network loops/overlapping networks discovered) this might be related to a bug (similar issues were reported on slightly older firmware revisions) so that you should upgrade the firmware as already suggested by Ede.
JPM
New Contributor

Hi, Yes I have checked the server and application logs and there does not appear to be any issues there. I will schedule a firmware upgrade of the firewalls and if this resolves this issue I will come back to the form and update his topic. Thank you everyone for your input - hopefully firmware upgrade will resolve this issue JP
Labels
Top Kudoed Authors