Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vvserpent
New Contributor II

replay packet drop

I have a 400A and running 4.0 MR4 P18 software. It is a new installation, as I don' t know what kind of traffic across the 400A. I configured " all-to-all" firewall rule and log all traffic to the FortiAnalyzer. On FortiAnalyzer, I found alot of " no sesssion matched" / " replay packet,drop" message. As there is no IPS / AV enabled, I have no idea what triggered the traffic drop... Anyone can tell me what wrong on my 400A ?
4 REPLIES 4
ede_pfau
SuperUser
SuperUser

hi, this might be IPsec VPN traffic not being answered. Does the Event Log show any VPN activity (only if VPN event logging is enabled)? BTW, there is no FOS 4.0 MR4, you probably meant 4.3.18. Is there any 4.3.18? Last time I checked latest version was 4.3.17. Anyway, FOS version does not matter here...
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

Ede yes it exist ( MR3 Patch 18 ) . Thanks to selective and me on PM, he updated me that p18 ) was out. Op, if this is vpn-ipsec related, what are you connecting to? Another fortigate or cisco?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
vvserpent
New Contributor II

Hi, There is no VPN connection yet. From the log message, the " replay packet(allow_err),drop" traffic is FTP service. itime=1409901317 date=2014-09-05 time=00:17:47 timestamp=1409901467 vd=ABCDE pri=warning type=traffic subtype=other app=N/A app_cat=N/A app_type=N/A carrier_ep=N/A device_id=FG400AXXXXXXX dst=192.168.xxx.35 dst_country=Reserved dst_int=port4 dst_port=21 dstname=192.168.xxx.35 dtime=1409876267 duration=5 group=N/A identidx=0 log_id=7 msg=" replay packet(allow_err), drop" perip_drop=0 perip_name=N/A policyid=1 profilegroup=N/A proto=6 rcvd=0 rule=1 sent=0 service=FTP shaper_drop_rcvd=0 shaper_drop_sent=0 shaper_rcvd_name=N/A shaper_sent_name=N/A SN=31670 src=10.0.xxx.68 src_country=Reserved src_int=port3 src_port=4588 srcname=10.0.xxx.68 status=deny subapp=N/A subappcat=N/A Regards, Jacky
TuncayBAS
Contributor II

please print follow code config system global get
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors