Sep 26 13:37:11 13:37:11.448495:CID-0:RT:flow_ipv4_del_flow: sess 34947, in hash 32 Sep 26 13:37:14 13:37:13.946565:CID-0:RT: Sep 26 13:37:14 13:37:13.946565:CID-0:RT:~~~FLOW <62.73.120.244/30588->46.10.161.40/83;6,0x0> matched filter IN(0) in root-logical-system for iif ge-0/0/0.0 of root-logical-system: Sep 26 13:37:14 13:37:13.946565:CID-0:RT: packet [52] ipid = 49974, @0x5edf201c Sep 26 13:37:14 13:37:13.946565:CID-0:RT:---- flow_process_pkt: (thd 2): flow_ctxt type 15, common flag 0x0, mbuf 0x5edf1e00, rtbl_idx = 0 Sep 26 13:37:14 13:37:13.946565:CID-0:RT:flow_process_pkt: COS val at start: fc: 0, dp: 0 Sep 26 13:37:14 13:37:13.946565:CID-0:RT: flow process pak fast ifl 77 in_ifp ge-0/0/0.0 Sep 26 13:37:14 13:37:13.946565:CID-0:RT: ge-0/0/0.0:62.73.120.244/30588->46.10.161.40/83, tcp, flag 2 syn Sep 26 13:37:14 13:37:13.946565:CID-0:RT: find flow: table 0x65c5c40, hash 21438(0xffff), sa 62.73.120.244, da 46.10.161.40, sp 30588, dp 83, proto 6, tok 8, conn-tag 0x00000000, vrf-grp-id 0 Sep 26 13:37:14 13:37:13.946565:CID-0:RT: no session found, start first path. in_tunnel - 0x0, from_cp_flag - 0 Sep 26 13:37:14 13:37:13.946704:CID-0:RT:check self-traffic on ge-0/0/0.0, in_tunnel 0x0 dp 83 Sep 26 13:37:14 13:37:13.946704:CID-0:RT:pak_for_self: No handler function found for proto:6, dst-port:83, drop pkt Sep 26 13:37:14 13:37:13.946704:CID-0:RT:retcode: 0x1 Sep 26 13:37:14 13:37:13.946704:CID-0:RT:pak_for_self : proto 6, dst port 83, action no action found, drop packet Sep 26 13:37:14 13:37:13.946704:CID-0:RT: flow_first_create_session Sep 26 13:37:14 13:37:13.946704:CID-0:RT:Save init hash spu id 0 to nsp and nsp2! Sep 26 13:37:14 13:37:13.946704:CID-0:RT:First path alloc and instl pending session, natp=0xbfafdd0, id=34949 Sep 26 13:37:14 13:37:13.946768:CID-0:RT: flow_first_in_dst_nat: in , out dst_adr 46.10.161.40, sp 30588, dp 83 Sep 26 13:37:14 13:37:13.946768:CID-0:RT: chose interface ge-0/0/0.0 as incoming nat if. Sep 26 13:37:14 13:37:13.946788:CID-0:RT:flow_first_rule_dst_xlate: DST xlate: 46.10.161.40(83) to 192.168.2.2(80), rule/pool id 1/1. Sep 26 13:37:14 13:37:13.946788:CID-0:RT:[JSF] Do ingress interest check. regd ingress plugins(2) Sep 26 13:37:14 13:37:13.946845:CID-0:RT:[JSF][0]plugins(0x0) enabled for session = 34949 implicit mask(0x0), service request(0x0) Sep 26 13:37:14 13:37:13.946845:CID-0:RT:-jsf : no plugin ingress interested for session 34949 Sep 26 13:37:14 13:37:13.946845:CID-0:RT:flow_first_routing: vr_id 0, call flow_route_lookup(): src_ip 62.73.120.244, x_dst_ip 192.168.2.2, in ifp ge-0/0/0.0, out ifp N/A sp 30588, dp 83, ip_proto 6, tos 0 Sep 26 13:37:14 13:37:13.946869:CID-0:RT:flow_first_routing: Doing DESTINATION addr route-lookup Sep 26 13:37:14 13:37:13.946869:CID-0:RT:flow_ipv4_rt_lkup success 192.168.2.2, iifl 0x4d, oifl 0x46 Sep 26 13:37:14 13:37:13.946869:CID-0:RT:flow_first_routing: setting out_vrf_id in lpak to 0, grp 0 Sep 26 13:37:14 13:37:13.946869:CID-0:RT: routed (x_dst_ip 192.168.2.2) from untrust (ge-0/0/0.0 in 0) to irb.0, Next-hop: 192.168.2.2 Sep 26 13:37:14 13:37:13.946927:CID-0:RT:Policy lkup: vsys 0 zone(8:untrust) -> zone(7:trust) scope:0 src vrf (0) dsv vrf (0) scope:0 Sep 26 13:37:14 13:37:13.946927:CID-0:RT: 62.73.120.244/30588 -> 192.168.2.2/80 proto 6 Sep 26 13:37:14 13:37:13.946940:CID-0:RT:Policy lkup: vsys 0 zone(5:global) -> zone(5:global) scope:0 src vrf (0) dsv vrf (0) scope:80 Sep 26 13:37:14 13:37:13.946940:CID-0:RT: 62.73.120.244/30588 -> 192.168.2.2/80 proto 6 Sep 26 13:37:14 13:37:13.946940:CID-0:RT:flow_first_policy_search: policy search from zone untrust-> zone trust (0x110,0x777c0053,0x50), result: 0xa357990, pending: 0?, is_http_cached = 0 Sep 26 13:37:14 13:37:13.946998:CID-0:RT:flow_first_policy_search: dynapp_none_policy: TRUE, uc_none_policy: TRUE, is_final: 0x0, is_explicit: 0x0, policy_meta_data: 0x0 Sep 26 13:37:14 13:37:13.946998:CID-0:RT: app 6, timeout 300s, curr ageout 20s Sep 26 13:37:14 13:37:13.946998:CID-0:RT: packet dropped, denied by policy Sep 26 13:37:14 13:37:13.946998:CID-0:RT: denied by policy default-policy-logical-system-00(2), dropping pkt Sep 26 13:37:14 13:37:13.946998:CID-0:RT: packet dropped, policy deny. Sep 26 13:37:14 13:37:13.947035:CID-0:RT:flow_initiate_first_path: first pak no session Sep 26 13:37:14 13:37:13.947035:CID-0:RT: flow find session returns error. Sep 26 13:37:14 13:37:13.947035:CID-0:RT:flow_proc_rc: -1. Sep 26 13:37:14 13:37:13.947064:CID-0:RT: ---- flow_process_pkt rc 0x7 (fp rc -1) Sep 26 13:37:14 13:37:14.210284:CID-0:RT: Sep 26 13:37:14 13:37:14.210284:CID-0:RT:~~~FLOW <62.73.120.244/32501->46.10.161.40/83;6,0x0> matched filter IN(0) in root-logical-system for iif ge-0/0/0.0 of root-logical-system: Sep 26 13:37:14 13:37:14.210284:CID-0:RT: packet [52] ipid = 49975, @0x5ee7ec9c Sep 26 13:37:14 13:37:14.210284:CID-0:RT:---- flow_process_pkt: (thd 2): flow_ctxt type 15, common flag 0x0, mbuf 0x5ee7ea80, rtbl_idx = 0 Sep 26 13:37:14 13:37:14.210284:CID-0:RT:flow_process_pkt: COS val at start: fc: 0, dp: 0 Sep 26 13:37:14 13:37:14.210284:CID-0:RT: flow process pak fast ifl 77 in_ifp ge-0/0/0.0 Sep 26 13:37:14 13:37:14.210284:CID-0:RT: ge-0/0/0.0:62.73.120.244/32501->46.10.161.40/83, tcp, flag 2 syn Sep 26 13:37:14 13:37:14.210284:CID-0:RT: find flow: table 0x65c5c40, hash 55787(0xffff), sa 62.73.120.244, da 46.10.161.40, sp 32501, dp 83, proto 6, tok 8, conn-tag 0x00000000, vrf-grp-id 0 Sep 26 13:37:14 13:37:14.210284:CID-0:RT: no session found, start first path. in_tunnel - 0x0, from_cp_flag - 0 Sep 26 13:37:14 13:37:14.210284:CID-0:RT:check self-traffic on ge-0/0/0.0, in_tunnel 0x0 dp 83 Sep 26 13:37:14 13:37:14.210284:CID-0:RT:pak_for_self: No handler function found for proto:6, dst-port:83, drop pkt Sep 26 13:37:14 13:37:14.210284:CID-0:RT:retcode: 0x1 Sep 26 13:37:14 13:37:14.210284:CID-0:RT:pak_for_self : proto 6, dst port 83, action no action found, drop packet Sep 26 13:37:14 13:37:14.210284:CID-0:RT: flow_first_create_session Sep 26 13:37:14 13:37:14.210284:CID-0:RT:Save init hash spu id 0 to nsp and nsp2! Sep 26 13:37:14 13:37:14.210284:CID-0:RT:First path alloc and instl pending session, natp=0xbfb0030, id=34950 Sep 26 13:37:14 13:37:14.210284:CID-0:RT: flow_first_in_dst_nat: in , out dst_adr 46.10.161.40, sp 32501, dp 83 Sep 26 13:37:14 13:37:14.210284:CID-0:RT: chose interface ge-0/0/0.0 as incoming nat if. Sep 26 13:37:14 13:37:14.210547:CID-0:RT:flow_first_rule_dst_xlate: DST xlate: 46.10.161.40(83) to 192.168.2.2(80), rule/pool id 1/1. Sep 26 13:37:14 13:37:14.210547:CID-0:RT:[JSF] Do ingress interest check. regd ingress plugins(2) Sep 26 13:37:14 13:37:14.210585:CID-0:RT:[JSF][0]plugins(0x0) enabled for session = 34950 implicit mask(0x0), service request(0x0) Sep 26 13:37:14 13:37:14.210615:CID-0:RT:-jsf : no plugin ingress interested for session 34950 Sep 26 13:37:14 13:37:14.210615:CID-0:RT:flow_first_routing: vr_id 0, call flow_route_lookup(): src_ip 62.73.120.244, x_dst_ip 192.168.2.2, in ifp ge-0/0/0.0, out ifp N/A sp 32501, dp 83, ip_proto 6, tos 0 Sep 26 13:37:14 13:37:14.210635:CID-0:RT:flow_first_routing: Doing DESTINATION addr route-lookup Sep 26 13:37:14 13:37:14.210635:CID-0:RT:flow_ipv4_rt_lkup success 192.168.2.2, iifl 0x4d, oifl 0x46 Sep 26 13:37:14 13:37:14.210635:CID-0:RT:flow_first_routing: setting out_vrf_id in lpak to 0, grp 0 Sep 26 13:37:14 13:37:14.210635:CID-0:RT: routed (x_dst_ip 192.168.2.2) from untrust (ge-0/0/0.0 in 0) to irb.0, Next-hop: 192.168.2.2 Sep 26 13:37:14 13:37:14.210635:CID-0:RT:Policy lkup: vsys 0 zone(8:untrust) -> zone(7:trust) scope:0 src vrf (0) dsv vrf (0) scope:0 Sep 26 13:37:14 13:37:14.210635:CID-0:RT: 62.73.120.244/32501 -> 192.168.2.2/80 proto 6 Sep 26 13:37:14 13:37:14.210714:CID-0:RT:Policy lkup: vsys 0 zone(5:global) -> zone(5:global) scope:0 src vrf (0) dsv vrf (0) scope:80 Sep 26 13:37:14 13:37:14.210714:CID-0:RT: 62.73.120.244/32501 -> 192.168.2.2/80 proto 6 Sep 26 13:37:14 13:37:14.210714:CID-0:RT:flow_first_policy_search: policy search from zone untrust-> zone trust (0x110,0x7ef50053,0x50), result: 0xa357990, pending: 0?, is_http_cached = 0 Sep 26 13:37:14 13:37:14.210714:CID-0:RT:flow_first_policy_search: dynapp_none_policy: TRUE, uc_none_policy: TRUE, is_final: 0x0, is_explicit: 0x0, policy_meta_data: 0x0 Sep 26 13:37:14 13:37:14.210774:CID-0:RT: app 6, timeout 300s, curr ageout 20s Sep 26 13:37:14 13:37:14.210774:CID-0:RT: packet dropped, denied by policy Sep 26 13:37:14 13:37:14.210774:CID-0:RT: denied by policy default-policy-logical-system-00(2), dropping pkt Sep 26 13:37:14 13:37:14.210785:CID-0:RT: packet dropped, policy deny. Sep 26 13:37:14 13:37:14.210785:CID-0:RT:flow_initiate_first_path: first pak no session Sep 26 13:37:14 13:37:14.210785:CID-0:RT: flow find session returns error. Sep 26 13:37:14 13:37:14.210785:CID-0:RT:flow_proc_rc: -1. Sep 26 13:37:14 13:37:14.210785:CID-0:RT: ---- flow_process_pkt rc 0x7 (fp rc -1) Sep 26 13:37:15 13:37:15.454794:CID-0:RT:jsf sess close notify Sep 26 13:37:15 13:37:15.454794:CID-0:RT:flow_ipv4_del_flow: sess 34949, in hash 32 Sep 26 13:37:15 13:37:15.454822:CID-0:RT:jsf sess close notify Sep 26 13:37:15 13:37:15.454822:CID-0:RT:flow_ipv4_del_flow: sess 34950, in hash 32