FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Note: The numbers in the braces  are the protocol number (ID) in decimal. Solution
For the example:
When set ipv4-proto-err drop is enabled, the following anomaly errors will be seen when running:
diag npu np6 anomaly-drop 0
IHP0: IHP1: IPV4_PROTO_ERR :0000000000000016  <-- HEX ID of 21 is not in the list of accepted protocols. IHP2: IHP3: XHP0: XHP1: HTX0: HTX1:
Note: The number in the braces are the protocol number (ID) in hexadecimal.
The result shows when an IP Packet defined as a Datagram Congestion Control Protocol is received, it is dropped because it has the HEX ID of 21 (decimal 33), which is not in the accepted protocol list.
A full list of protocol numbers are available here.
Further information is available in the following links: