Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
evince
New Contributor

Session clash

Hi all,

 

With my fortiVM, i can see a lot of session clash, can you tell me what does this error mean?

 

Thank you in advance,

2 REPLIES 2
emnoc
Esteemed Contributor III

Are you seeing this from the diag cmd

 

e.g

 

diag sys session stat misc info:     session_count=21849 setup_rate=99 exp_count=0 clash=889     memory_tension_drop=0 ephemeral=0/57344 removeable=0  ha_scan=0 delete=0, flush=0, dev_down=0/0 TCP sessions:      127 in ESTABLISHED state      30 in SYN_SENT state      1 in FIN_WAIT state      8 in TIME_WAIT state      2 in CLOSE state      4 in CLOSE_WAIT state firewall error stat: error1=00000000 error2=00000000 error3=00000000 error4=00000000 tt=00000000 cont=00000000 ids_recv=19209c98 url_recv=00000000 av_recv=00000077 fqdn_count=00000000 tcp reset stat:     syncqf=1 acceptqf=0 no-listener=9282 data=0 ses=0 ips=0 global: ses_limit=0 ses6_limit=0 rt_limit=0 rt6_limit=0

 

This means you have ephemeral port exhausation. I would look at the following;

 

 

1: infection or malware/botagents/etc

2: session ttl

3: I would monitor the ephemeral counter very closely

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
evince
New Contributor

Hello emnoc and thank you for your help, here is the result of the diag command :

 

FGVM-ITX (global) # diag sys session stat 
misc info:	 session_count=3257 setup_rate=154 exp_count=30 clash=69
	memory_tension_drop=0 ephemeral=0/327680 removeable=0
delete=0, flush=0, dev_down=0/0
TCP sessions:
	 28 in NONE state
	 858 in ESTABLISHED state
	 37 in SYN_SENT state
	 2 in SYN_RECV state
	 1 in FIN_WAIT state
	 95 in TIME_WAIT state
	 73 in CLOSE state
	 23 in CLOSE_WAIT state
firewall error stat:
error1=00000000
error2=00000000
error3=00000000
error4=00000000
tt=00000000
cont=000bf364
ids_recv=02f802e3
url_recv=00000000
av_recv=0053144c
fqdn_count=00000001
tcp reset stat:
	syncqf=406 acceptqf=0 no-listener=5245 data=0 ses=2 ips=0
global: ses_limit=0 ses6_limit=0 rt_limit=0 rt6_limit=0
Labels
Top Kudoed Authors