****** 11197.0: packet received [64]****** ipid = 45033(afe9), @0d60f114 packet passed sanity check. flow_decap_vector IPv4 process ethernet0/9:A.B.C.D/15649->x.x.2.1/443,6 no session found flow_first_sanity_check: in , out chose interface ethernet0/9 as incoming nat if. flow_first_routing: in , out search route to (ethernet0/9, A.B.C.D->x.x.2.1) in vr trust-vr for vsd-0/flag-0/ifp-null [ Dest] 22.route x.x.2.1->x.x.2.1, to ethernet0/8 routed (x_dst_ip x.x.2.1) from ethernet0/9 (ethernet0/9 in 0) to ethernet0/8 policy search from zone 1-> zone 2 policy_flow_search policy search nat_crt from zone 1-> zone 2 RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip x.x.2.1, port 443, proto 6) No SW RPC rule match, search HW rule swrs_search_ip: policy matched id/idx/action = 320000/-1/0x0 Searching global policy. swrs_search_ip: policy matched id/idx/action = 320000/-1/0x0 policy id (320000) packet dropped, denied by policy Policy id deny policy, ipv6 0, flow_potential_violation 0 11197.0: ethernet0/9(i) len=78:000600060001->5c5eabe5c18d/0800 A.B.C.D -> x.x.2.1/6 vhl=45, tos=00, id=50563, frag=4000, ttl=52 tlen=64 tcp:ports 15649->443, seq=2264516501, ack=0, flag=b002/SYN 5c 5e ab e5 c1 8d 00 06 00 06 00 01 08 00 45 00 \^............E. 00 40 c5 83 40 00 34 06 a9 e8 42 57 45 99 b8 b7 .@..@.4...BWE... 96 a4 3d 21 01 bb 86 f9 c7 95 00 00 00 00 b0 02 ..=!............ ff ff ed 9f 00 00 02 04 05 6c 01 03 03 05 01 01 .........l...... 08 0a 26 be be 2f 00 00 00 00 04 02 00 00 ..&../........