root# run show log tracefile Apr 22 09:41:28 clear-log[3248]: logfile cleared Apr 22 09:41:34 09:41:34.144487:CID-0:RT:<192.168.7.196/50267->192.168.12.199/443;6> matched filter p1: Apr 22 09:41:34 09:41:34.144487:CID-0:RT:packet [52] ipid = 2492, @0x423f5a9c Apr 22 09:41:34 09:41:34.144487:CID-0:RT:---- flow_process_pkt: (thd 3): flow_ctxt type 15, common flag 0x0, mbuf 0x423f5880, rtbl_idx = 6 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: flow process pak fast ifl 85 in_ifp ge-0/0/14.0 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: ge-0/0/14.0:192.168.7.196/50267->192.168.12.199/443, tcp, flag 2 syn Apr 22 09:41:34 09:41:34.144692:CID-0:RT: find flow: table 0x4917dd98, hash 46929(0xffff), sa 192.168.7.196, da 192.168.12.199, sp 50267, dp 443, proto 6, tok 7 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: no session found, start first path. in_tunnel - 0x0, from_cp_flag - 0 Apr 22 09:41:34 09:41:34.144692:CID-0:RT:check self-traffic on ge-0/0/14.0, in_tunnel 0x0 Apr 22 09:41:34 09:41:34.144692:CID-0:RT:retcode: 0x104 Apr 22 09:41:34 09:41:34.144692:CID-0:RT:pak_for_self : proto 6, dst port 443, action 0x4 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: flow_first_create_session Apr 22 09:41:34 09:41:34.144692:CID-0:RT:First path alloc and instl pending session, natp=0x4bb15a20, id=9070 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: flow_first_in_dst_nat: in , out dst_adr 192.168.12.199, sp 50267, dp 443 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: chose interface ge-0/0/14.0 as incoming nat if. Apr 22 09:41:34 09:41:34.144692:CID-0:RT:flow_first_rule_dst_xlate: DST xlate: 192.168.12.199(443) to 192.168.6.11(443), rule/pool id 2/1. Apr 22 09:41:34 09:41:34.144692:CID-0:RT:flow_first_routing: vr_id 6, call flow_route_lookup(): src_ip 192.168.7.196, x_dst_ip 192.168.6.11, in ifp ge-0/0/14.0, out ifp N/A sp 50267, dp 443, ip_proto 6, tos 0 Apr 22 09:41:34 09:41:34.144692:CID-0:RT:Doing DESTINATION addr route-lookup Apr 22 09:41:34 09:41:34.144692:CID-0:RT:flow_ipv4_rt_lkup success 192.168.6.11, iifl 0x55, oifl 0x46 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: routed (x_dst_ip 192.168.6.11) from untrust (ge-0/0/14.0 in 0) to vlan.0, Next-hop: 192.168.6.11 Apr 22 09:41:34 09:41:34.144692:CID-0:RT:flow_first_policy_search: policy search from zone untrust-> zone trust (0x110,0xc45b01bb,0x1bb) Apr 22 09:41:34 09:41:34.144692:CID-0:RT:Policy lkup: vsys 0 zone(7:untrust) -> zone(6:trust) scope:0 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: 192.168.7.196/50267 -> 192.168.6.11/443 proto 6 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: policy has timeout 900 Apr 22 09:41:34 09:41:34.144692:CID-0:RT: app 58, timeout 1800s, curr ageout 20s Apr 22 09:41:34 09:41:34.145186:CID-0:RT: permitted by policy publish(5) Apr 22 09:41:34 09:41:34.145186:CID-0:RT: packet passed, Permitted by policy. Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_src_xlate: nat_src_xlated: False, nat_src_xlate_failed: False Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_src_xlate: incoming src port is : 50267. Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_src_xlate: src nat returns status: 0, rule/pool id: 0/0, pst_nat: False. Apr 22 09:41:34 09:41:34.145186:CID-0:RT: dip id = 0/0, 192.168.7.196/50267->192.168.7.196/50267 protocol 0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: choose interface vlan.0(P2P) as outgoing phy if Apr 22 09:41:34 09:41:34.145186:CID-0:RT:is_loop_pak: No loop: on ifp: vlan.0, addr: 192.168.6.11, rtt_idx:0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:-jsf : Alloc sess plugin info for session 9070 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:[JSF]Normal interest check. regd plugins 27, enabled impl mask 0x0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:+++++++++++jsf_test_plugin_data_evh: 3 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:[JSF]Plugins(0x0, count 0) enabled for session = 543329236, impli mask(0x0), post_nat cnt 9070 svc req(0x0) Apr 22 09:41:34 09:41:34.145186:CID-0:RT:-jsf : no plugin interested for session 9070, free sess plugin info Apr 22 09:41:34 09:41:34.145186:CID-0:RT: service lookup identified service 58. Apr 22 09:41:34 09:41:34.145186:CID-0:RT: flow_first_final_check: in , out Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_final_check: flow_set_xlate_vector. Apr 22 09:41:34 09:41:34.145186:CID-0:RT:In flow_first_complete_session Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_complete_session: pak_ptr is xlated packet Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_first_complete_session, pak_ptr: 0x48ae9eb0, nsp: 0x4bb15a20, in_tunnel: 0x0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:construct v4 vector for nsp2 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: existing vector list 0x1002-0x45ea8f58. Apr 22 09:41:34 09:41:34.145186:CID-0:RT: Session (id:9070) created for first pak 1002 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:first pak processing successful Apr 22 09:41:34 09:41:34.145186:CID-0:RT: flow_first_install_session======> 0x4bb15a20 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: nsp 0x4bb15a20, nsp2 0x4bb15aa4 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: make_nsp_ready_no_resolve() Apr 22 09:41:34 09:41:34.145186:CID-0:RT:flow_ipv4_rt_lkup success 192.168.7.196, iifl 0x55, oifl 0x56 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: route lookup: dest-ip 192.168.7.196 orig ifp ge-0/0/14.0 output_ifp ge-0/0/15.0 orig-zone 7 out-zone 7 vsd 0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: reroute handling for tunnel 0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: clearing tunnel since the routed interface is ge-0/0/15.0 Apr 22 09:41:34 09:41:34.145186:CID-0:RT: route to 217.150.139.161 Apr 22 09:41:34 09:41:34.145186:CID-0:RT:no need update ha Apr 22 09:41:34 09:41:34.145186:CID-0:RT:Installing c2s NP session wing Apr 22 09:41:34 09:41:34.145186:CID-0:RT:Installing s2c NP session wing Apr 22 09:41:34 09:41:34.145679:CID-0:RT:get NULL sess plugin info 0x4bb15a20 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:get NULL sess plugin info 0x4bb15a20 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:get NULL sess plugin info 0x4bb15a20 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:first path session installation succeeded Apr 22 09:41:34 09:41:34.145679:CID-0:RT: flow got session. Apr 22 09:41:34 09:41:34.145679:CID-0:RT: flow session id 9070 Apr 22 09:41:34 09:41:34.145679:CID-0:RT: vector bits 0x1002 vector 0x45ea8f58 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:flow_tcp_wsf_update: wsf 8 Apr 22 09:41:34 09:41:34.145679:CID-0:RT: tcp 3way refresh, is_half_open:0, is_fwauth:0 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:flow_xlate_pak Apr 22 09:41:34 09:41:34.145679:CID-0:RT: post addr xlation: 192.168.7.196->192.168.6.11. Apr 22 09:41:34 09:41:34.145679:CID-0:RT: post addr xlation: 192.168.7.196->192.168.6.11. Apr 22 09:41:34 09:41:34.145679:CID-0:RT:pre-frag not needed: ipsize: 52, mtu: 1500, nsp2->pmtu: 1500 Apr 22 09:41:34 09:41:34.145679:CID-0:RT:mbuf 0x423f5880, exit nh 0x120010 Apr 22 09:41:34 09:41:34.145679:CID-0:RT: ----- flow_process_pkt rc 0x0 (fp rc 0)