nsisg1000(M)-> cl db nsisg1000(M)-> get ff Flow filter based on: id:0 dst ip 10.1.32.10 ip proto 17 id:1 src ip 10.1.32.10 ip proto 17 nsisg1000(M)-> debug flow basic nsisg1000(M)-> All debug off get db str ****** 88730.0: packet received [328]****** ipid = 43026(a812), @6b6887a4 flow_self_vector2: send pack with current vid =0, enc_size:0 processing packet through normal path. dhcp client 2 server traffic. packet passed sanity check. self:10.1.32.1/67->10.1.32.10/67,17 no session found created new session from self 524286 rs_search_ip : no rms ctx! (rms_ctx 0, rule cnt 0) rs_search_ip : no rms ctx! (rms_ctx 0, rule cnt 0) policy id = 320000(Deny), tunnel = 0 search route to (null, 0.0.0.0->10.1.32.10) in vr trust-vr for vsd-0/flag-2000 /ifp-ethernet1/1 [ Dest] 4.route 10.1.32.10->10.1.32.10, to ethernet1/1 routed 10.1.32.10 next hop 10.1.32.10, from self existing vector list 20-195518b4. processing packet from self flow_first_install_session======> route to 10.1.32.10 arp entry found for 10.1.32.10 ifp2 ethernet1/1, out_ifp ethernet1/1, flag 00800600, tunnel ffffffff, rc 1 outgoing wing prepared, ready Success installing work and forward sessions nsrp msg sent. flow got session. flow session id 524286 skip ttl adjust for packet from self. post addr xlation: 10.1.32.1->10.1.32.10. flow_send_vector_, vid = 0, is_layer2_if=0 packet send out to 0019b9eae72c through ethernet1/1 **st: 4d9c118: 1289:10.1.32.10/43->10.1.48.1/43,17,32 8 ****** 88730.0: packet received [328]****** ipid = 4745(1289), @04d9c118 packet passed sanity check. ethernet1/1:10.1.32.10/67->10.1.48.1/67,17 no session found flow_first_sanity_check: in , out chose interface ethernet1/1 as incoming nat if. flow_first_routing: in , out search route to (ethernet1/1, 10.1.32.10->10.1.48.1) in vr trust-vr for vsd-0/ flag-0/ifp-null [ Dest] 9.route 10.1.48.1->10.1.48.1, to aggregate1.3 routed (x_dst_ip 10.1.48.1) from ethernet1/1 (ethernet1/1 in 0) to aggregate1. 3 policy search from zone 2-> zone 3 policy_flow_search policy search nat_crt from zone 2-> zone 3 RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 10.1 .48.1, port 67, proto 17) No SW RPC rule match, search HW rule rs_search_ip: policy matched id/idx/action = 1/0/0x1 Permitted by policy 1 dip id = 2, 10.1.32.10/67->10.1.48.1/16277 choose interface aggregate1.3 as outgoing phy if check nsrp pak fwd: in_tun=0xffffffff, VSD 0 for out ifp aggregate1.3 vsd 0 is active set interface aggregate1.3 as loop ifp. session application type 28, name None, nas_id 0, timeout 60sec ALG vector is not attached service lookup identified service 0. flow_first_final_check: in , out SM_RULE:0 existing vector list 21-195518d4. Session (id:524282) created for first pak 21 loopback session processing post addr xlation: 10.1.48.1->10.1.48.1. flow_first_sanity_check: in , out SELF_APP_SVR_DHCPRELAY can't accept it, return 0 chose interface aggregate1.3 as incoming nat if. packet dropped: for self but not interested loopback session failed ****** 88733.0: packet received [328]****** ipid = 43029(a815), @6b688d84 flow_self_vector2: send pack with current vid =0, enc_size:0 processing packet through normal path. dhcp client 2 server traffic. packet passed sanity check. self:10.1.32.1/67->10.1.32.10/67,17 existing session found. sess token 5 flow got session. flow session id 524286 skip ttl adjust for packet from self. post addr xlation: 10.1.32.1->10.1.32.10. flow_send_vector_, vid = 0, is_layer2_if=0 packet send out to 0019b9eae72c through ethernet1/1 **st: 4d9c118: 12be:10.1.32.10/43->10.1.48.1/43,17,32 8 ****** 88733.0: packet received [328]****** ipid = 4798(12be), @04d9c118 packet passed sanity check. ethernet1/1:10.1.32.10/67->10.1.48.1/67,17 no session found flow_first_sanity_check: in , out chose interface ethernet1/1 as incoming nat if. flow_first_routing: in , out search route to (ethernet1/1, 10.1.32.10->10.1.48.1) in vr trust-vr for vsd-0/ flag-0/ifp-null [ Dest] 9.route 10.1.48.1->10.1.48.1, to aggregate1.3 routed (x_dst_ip 10.1.48.1) from ethernet1/1 (ethernet1/1 in 0) to aggregate1. 3 policy search from zone 2-> zone 3 policy_flow_search policy search nat_crt from zone 2-> zone 3 RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 10.1 .48.1, port 67, proto 17) No SW RPC rule match, search HW rule rs_search_ip: policy matched id/idx/action = 1/0/0x1 Permitted by policy 1 dip id = 2, 10.1.32.10/67->10.1.48.1/22370 choose interface aggregate1.3 as outgoing phy if check nsrp pak fwd: in_tun=0xffffffff, VSD 0 for out ifp aggregate1.3 vsd 0 is active set interface aggregate1.3 as loop ifp. session application type 28, name None, nas_id 0, timeout 60sec ALG vector is not attached service lookup identified service 0. flow_first_final_check: in , out SM_RULE:0 existing vector list 21-195518d4. Session (id:524282) created for first pak 21 loopback session processing post addr xlation: 10.1.48.1->10.1.48.1. flow_first_sanity_check: in , out SELF_APP_SVR_DHCPRELAY can't accept it, return 0 chose interface aggregate1.3 as incoming nat if. packet dropped: for self but not interested loopback session failed ****** 88741.0: packet received [328]****** ipid = 43031(a817), @6b6887a4 flow_self_vector2: send pack with current vid =0, enc_size:0 processing packet through normal path. dhcp client 2 server traffic. packet passed sanity check. self:10.1.32.1/67->10.1.32.10/67,17 existing session found. sess token 5 flow got session. flow session id 524286 skip ttl adjust for packet from self. post addr xlation: 10.1.32.1->10.1.32.10. flow_send_vector_, vid = 0, is_layer2_if=0 packet send out to 0019b9eae72c through ethernet1/1 **st: 4d9c118: 1448:10.1.32.10/43->10.1.48.1/43,17,32 8 ****** 88741.0: packet received [328]****** ipid = 5192(1448), @04d9c118 packet passed sanity check. ethernet1/1:10.1.32.10/67->10.1.48.1/67,17 no session found flow_first_sanity_check: in , out chose interface ethernet1/1 as incoming nat if. flow_first_routing: in , out search route to (ethernet1/1, 10.1.32.10->10.1.48.1) in vr trust-vr for vsd-0/ flag-0/ifp-null [ Dest] 9.route 10.1.48.1->10.1.48.1, to aggregate1.3 routed (x_dst_ip 10.1.48.1) from ethernet1/1 (ethernet1/1 in 0) to aggregate1. 3 policy search from zone 2-> zone 3 policy_flow_search policy search nat_crt from zone 2-> zone 3 RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 10.1 .48.1, port 67, proto 17) No SW RPC rule match, search HW rule rs_search_ip: policy matched id/idx/action = 1/0/0x1 Permitted by policy 1 dip id = 2, 10.1.32.10/67->10.1.48.1/39932 choose interface aggregate1.3 as outgoing phy if check nsrp pak fwd: in_tun=0xffffffff, VSD 0 for out ifp aggregate1.3 vsd 0 is active set interface aggregate1.3 as loop ifp. session application type 28, name None, nas_id 0, timeout 60sec ALG vector is not attached service lookup identified service 0. flow_first_final_check: in , out SM_RULE:0 existing vector list 21-195518d4. Session (id:524282) created for first pak 21 loopback session processing post addr xlation: 10.1.48.1->10.1.48.1. flow_first_sanity_check: in , out SELF_APP_SVR_DHCPRELAY can't accept it, return 0 chose interface aggregate1.3 as incoming nat if. packet dropped: for self but not interested loopback session failed ****** 88756.0: packet received [328]****** ipid = 43035(a81b), @6b688d84 flow_self_vector2: send pack with current vid =0, enc_size:0 processing packet through normal path. dhcp client 2 server traffic. packet passed sanity check. self:10.1.32.1/67->10.1.32.10/67,17 existing session found. sess token 5 flow got session. flow session id 524286 skip ttl adjust for packet from self. post addr xlation: 10.1.32.1->10.1.32.10. flow_send_vector_, vid = 0, is_layer2_if=0 packet send out to 0019b9eae72c through ethernet1/1 **st: 4d9c118: 1581:10.1.32.10/43->10.1.48.1/43,17,32 8 ****** 88756.0: packet received [328]****** ipid = 5505(1581), @04d9c118 packet passed sanity check. ethernet1/1:10.1.32.10/67->10.1.48.1/67,17 no session found flow_first_sanity_check: in , out chose interface ethernet1/1 as incoming nat if. flow_first_routing: in , out search route to (ethernet1/1, 10.1.32.10->10.1.48.1) in vr trust-vr for vsd-0/ flag-0/ifp-null [ Dest] 9.route 10.1.48.1->10.1.48.1, to aggregate1.3 routed (x_dst_ip 10.1.48.1) from ethernet1/1 (ethernet1/1 in 0) to aggregate1. 3 policy search from zone 2-> zone 3 policy_flow_search policy search nat_crt from zone 2-> zone 3 RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 10.1 .48.1, port 67, proto 17) No SW RPC rule match, search HW rule rs_search_ip: policy matched id/idx/action = 1/0/0x1 Permitted by policy 1 dip id = 2, 10.1.32.10/67->10.1.48.1/43063 choose interface aggregate1.3 as outgoing phy if check nsrp pak fwd: in_tun=0xffffffff, VSD 0 for out ifp aggregate1.3 vsd 0 is active set interface aggregate1.3 as loop ifp. session application type 28, name None, nas_id 0, timeout 60sec ALG vector is not attached service lookup identified service 0. flow_first_final_check: in , out SM_RULE:0 existing vector list 21-195518d4. Session (id:524282) created for first pak 21 loopback session processing post addr xlation: 10.1.48.1->10.1.48.1. flow_first_sanity_check: in , out SELF_APP_SVR_DHCPRELAY can't accept it, return 0 chose interface aggregate1.3 as incoming nat if. packet dropped: for self but not interested loopback session failed ****** 88771.0: packet received [207]****** ipid = 5970(1752), @8054b118 other ip packet handle. ****** 88801.0: packet received [207]****** ipid = 6923(1b0b), @805ba118 other ip packet handle. nsisg1000(M)->