SRX Services Gateway
Highlighted
SRX Services Gateway

srx to srx site-site vpn is up but no traffic

‎12-28-2018 07:38 PM

On the SRX-SRX tunnel if this is a route based tunnel using st0.x interfaces please confirm that a route to the remote site is installed on both sides pointing to the tunnel.

i checked beflow url and noted issue at level 7 ,  how to check and change policy order ? i don't have web-ui access to it, can any one tell me , how to check and change oder , #insert option giving me errors

 

https://kb.juniper.net/InfoCenter/index?page=content&id=KB10093&actp=METADATA

21 REPLIES 21
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 12:16 AM

are you using traffic-selectors? if not you have manually add the route pointing to st0.x

 

 

for policy re-order, you can do below.

 

[edit]
root@srx# edit security policies from-zone trust to-zone untrust          

[edit security policies from-zone trust to-zone untrust]
root@srx# insert policy "policyname" before/after "policyname"

 

[edit security policies from-zone trust to-zone untrust]
root@srx#top

 

[edit ]
root@srx#commit

 

 

Please share the error details if this is not working for you.

 

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 02:18 AM

This is my existing security policies , are these in correct order ? trust to vpn.india, vpn.idnia to trust working fine, need to ping 192.168.50.x to 200.x vice-versa
 
On SRX - A
@srx> show security ike security-associations
Index   Remote Address  State  Initiator cookie  Responder cookie  Mode
25      x.x.x.x  UP     1d2519d6072473ed  fdc4923c159c6953  Main         
1       y.y.y.y   UP     f63cd6b0dc404ddf  d7706ba53745926e  Main
 
@srx> show security ipsec security-associations    
  Total active tunnels: 2
  ID    Gateway          Port  Algorithm       SPI      Life:sec/kb  Mon vsys
  <131073 x.x.x.x  500   ESP:des/ sha1   bc0c116  79456/unlim   -   root
  >131073 x.x.x.x  500   ESP:des/ sha1   483b1741 79456/unlim   -   root
  <131074 y.y.y.y 500   ESP:3des/sha1   2ac9a532 3137/ unlim   -   root
  >131074 y.y.y.y  500   ESP:3des/sha1   b403cb9b 3137/ unlim   -   root

@srx> show security policies
Default policy: deny-all
From zone: trust, To zone: untrust
  Policy: trust-to-untrust, State: enabled, Index: 4, Scope Policy: 0, Sequence number: 1
    Source addresses: any
    Destination addresses: any
    Applications: any
    Action: permit
From zone: trust, To zone: vpn.india
  Policy: trust-vpn-india-cfgr, State: enabled, Index: 5, Scope Policy: 0, Sequence number: 1
    Source addresses: net-cfgr_192-168-50-0--24
    Destination addresses: net-cfgr_192-168-2-0--24, net-cfgr_192-168-6-0--24
    Applications: any
    Action: permit
From zone: trust, To zone: vpn
  Policy: trust-vpn-cfgr, State: enabled, Index: 8, Scope Policy: 0, Sequence number: 1
    Source addresses: net-cfgr_192-168-50-0--24
    Destination addresses: net-cfgr_192-168-200-0--24
    Applications: any
    Action: permit
From zone: vpn.india, To zone: trust
  Policy: vpn-india-trust-cfgr, State: enabled, Index: 6, Scope Policy: 0, Sequence number: 1
    Source addresses: net-cfgr_192-168-2-0--24, net-cfgr_192-168-6-0--24
    Destination addresses: net-cfgr_192-168-50-0--24
    Applications: any
    Action: permit
From zone: untrust, To zone: trust
  Policy: ov-access, State: enabled, Index: 7, Scope Policy: 0, Sequence number: 1
    Source addresses: any
    Destination addresses: ov-server
    Applications: any
    Action: permit
From zone: vpn, To zone: trust
  Policy: vpn-trust-cfgr, State: enabled, Index: 9, Scope Policy: 0, Sequence number: 1
    Source addresses: net-cfgr_192-168-200-0--24
    Destination addresses: net-cfgr_192-168-50-0--24
    Applications: any
    Action: permit

SRX- B

root@ocdc> show security ike security-associations                                      
Index   State  Initiator cookie  Responder cookie  Mode           Remote Address   
1717675 UP     1d2519d6072473ed  fdc4923c159c6953  Main           y.y.y.y   
1717645 UP     5554564b41f144aa  96cadcfc816196b7  Main           x.x.x.x

root@ocdc> show security ipsec security-associations
  Total active tunnels: 2
  ID    Algorithm       SPI      Life:sec/kb  Mon lsys Port  Gateway   
  <131074 ESP:3des/sha1 f152261d 1765/ unlim   -   root 500   x.x.x.x   
  >131074 ESP:3des/sha1 483b1743 1765/ unlim   -   root 500   x.x.x.x   
  <131073 ESP:3des/sha1 b403cb9b 2794/ unlim   -   root 500   y.y.y.y  
  >131073 ESP:3des/sha1 2ac9a532 2794/ unlim   -   root 500   y.y.y.y

@srxB> show security policies
Default policy: deny-all
From zone: Internal, To zone: Internet
  Policy: All_Internal_Internet, State: enabled, Index: 5, Scope Policy: 0, Sequence number: 1
    Source addresses: any
    Destination addresses: any
    Applications: any
    Action: permit
From zone: Internal, To zone: Internal
  Policy: route-11, State: enabled, Index: 8, Scope Policy: 0, Sequence number: 1
    Source addresses: any
    Destination addresses: int-11-net
    Applications: any
    Action: permit
From zone: Internal, To zone: vpn.hyd
  Policy: Internal-hyd-corp-vpn, State: enabled, Index: 10, Scope Policy: 0, Sequence number: 1
    Source addresses: int-200-net, int-201-net, int-203-net, int-11-net
    Destination addresses: net-cfgr_192-168-2-0--24, net-cfgr_192-168-6-0--24
    Applications: any
    Action: permit
From zone: Internal, To zone: us-corp-vpn
  Policy: internal-us-corp-vpn, State: enabled, Index: 4, Scope Policy: 0, Sequence number: 1
    Source addresses: int-200-net, int-11-net
    Destination addresses: us-corp-50-net
    Applications: any
    Action: permit
From zone: Internet, To zone: Internal
  Policy: ov-access, State: enabled, Index: 6, Scope Policy: 0, Sequence number: 1
    Source addresses: any
    Destination addresses: ov-server
    Applications: any
    Action: permit
From zone: vpn.hyd, To zone: Internal
  Policy: hyd-corp-vpn-Internal-vpn, State: enabled, Index: 9, Scope Policy: 0, Sequence number: 1
    Source addresses: net-cfgr_192-168-2-0--24, net-cfgr_192-168-6-0--24
    Destination addresses: int-200-net, int-201-net, int-203-net, int-11-net
    Applications: any
    Action: permit
From zone: us-corp-vpn, To zone: Internal
  Policy: us-corp-vpn-Internal-vpn, State: enabled, Index: 7, Scope Policy: 0, Sequence number: 1
    Source addresses: us-corp-50-net
    Destination addresses: int-200-net, int-11-net
    Applications: any
    Action: permit


Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 02:41 AM

Can you conffirm the below.

 

Zone associated with st0.x

Zone associated with your LAN interface

Zone associated with your VPN external interface

Do you have the route configured pointing to st0.x?

 

 

 

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 02:55 AM

SRX " A"

@srx# show security zones security-zone vpn   
address-book {
    address net-cfgr_192-168-200-0--24 192.168.200.0/24;
    address net-cfgr_192-168-11-0--24 192.168.11.0/24;
}
interfaces {
    st0.0;
}

 

> show route

192.168.200.0/24   *[Static/5] 01:42:16
                    > via st0.0

 

SRX B

@srx# show security zones security-zone us-c-vpn
address-book {
    address corp-50-net 192.168.50.0/24;
}

interfaces {
    st0.0;
}

 

 

> show toure

 

192.168.50.0/24    *[Static/5] 01:41:20
                    > via st0.0




Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 03:05 AM
I believe “us-corp-vpn” and “ us-c-vpn” are same , if so the policies look good.

Can you share below output from both SRX? Take it 2 times while the Ping is running from both sides.

show security ipsec statistics
Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

[ Edited ]
‎12-29-2018 03:15 AM

this is 200.x ip

SRX  A

@srx> show security ipsec statistics    
ESP Statistics:
  Encrypted bytes:       2646429520
  Decrypted bytes:       1440300668
  Encrypted packets:      577440958
  Decrypted packets:      509664398
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 278
  ESP authentication failures: 452, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

@srx> show security ipsec statistics    
ESP Statistics:
  Encrypted bytes:       2646445600
  Decrypted bytes:       1440304752
  Encrypted packets:      577440978
  Decrypted packets:      509664414
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 278
  ESP authentication failures: 452, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

 

this si 50.x ip

root@oc-corp-srx> show security ipsec statistics              
ESP Statistics:
  Encrypted bytes:           285376
  Decrypted bytes:           149865
  Encrypted packets:           2392
  Decrypted packets:           2284
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

@oc-corp-srx> show security ipsec statistics    
ESP Statistics:
  Encrypted bytes:           285376
  Decrypted bytes:           149865
  Encrypted packets:           2392
  Decrypted packets:           2284
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

@oc-corp-srx> show security ipsec statistics    
ESP Statistics:
  Encrypted bytes:           285376
  Decrypted bytes:           149865
  Encrypted packets:           2392
  Decrypted packets:           2284
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 03:27 AM
Since we have 2 tunnels on both sides, can you confirm the tunnel between SRX A and SRX B as below?
On SRX A

<131074 y.y.y.y 500 ESP:3des/sha1 2ac9a532 3137/ unlim - root
>131074 y.y.y.y 500 ESP:3des/sha1 b403cb9b 3137/ unlim - root

And On SRX B

<131073 ESP:3des/sha1 b403cb9b 2794/ unlim - root 500 y.y.y.y
>131073 ESP:3des/sha1 2ac9a532 2794/ unlim - root 500 y.y.y.y


If so can you share below outputs?


From SRX A

show security ipsec statistics index 131074

on SRX B

show security ipsec statistics index 131073


Collect these 2 multiple times while the Ping is running
Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 03:34 AM

@oc-corp-srx> show security ipsec statistics index 131074    
ESP Statistics:
  Encrypted bytes:            18512
  Decrypted bytes:              580
  Encrypted packets:            137
  Decrypted packets:              9
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

@oc-corp-srx> show security ipsec statistics index 131074    
ESP Statistics:
  Encrypted bytes:            18512
  Decrypted bytes:              748
  Encrypted packets:            137
  Decrypted packets:             11
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

 

r@srx> show security ipsec statistics index 131073
ESP Statistics:
  Encrypted bytes:              384
  Decrypted bytes:                0
  Encrypted packets:              4
  Decrypted packets:              0
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

@srx> show security ipsec statistics index 131073    
ESP Statistics:
  Encrypted bytes:              384
  Decrypted bytes:                0
  Encrypted packets:              4
  Decrypted packets:              0
AH Statistics:
  Input bytes:                    0
  Output bytes:                   0
  Input packets:                  0
  Output packets:                 0
Errors:
  AH authentication failures: 0, Replay errors: 0
  ESP authentication failures: 0, ESP decryption failures: 0
  Bad headers: 0, Bad trailers: 0

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 05:14 AM
Any clue ?
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 05:20 AM
Can you do “restart ipsec key-management” on below SRX/site?

r@srx> show security ipsec statistics index 131073
Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 06:47 AM
This ipsec tunnel was down. Not coming up, inLogs - local IKE-KD not available, remote IKE-KD not available, Vr-ID:0
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

[ Edited ]
‎12-29-2018 08:46 AM

nothing happend, ipsec association came up but same result

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 09:17 AM

It looks like you have two different vpn gateways setup on the device.

Can you confirm you are using different st0.x interfaces for the two different tunnels?

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 09:26 AM

yes, st0.0 & st0.2 tunnles using for both gateways

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

[ Edited ]
‎12-29-2018 09:44 AM

Same configuration same &  boxes (ssg5 & srx )are there from past 2years, but we have encountered this issue recently.

trio directional ( ssg5 to srx A , srx A to srx B, srx B to ssg5 ). all gw and ip subnets, tunnels are same.

SRX " A"

r@corp-srx> show security ipsec security-associations    
  Total active tunnels: 2
  ID    Gateway          Port  Algorithm       SPI      Life:sec/kb  Mon vsys
  <131073 x.x.x.x  500   ESP:des/ sha1   1a0028d1 67652/unlim   -   root
  >131073 x.x.x.x 500   ESP:des/ sha1   483b174d 67652/unlim   -   root
  <131074 z.z.z.z 500   ESP:3des/sha1   f9dfd727 2600/ unlim   -   root
  >131074 z.z.z.z 500   ESP:3des/sha1   afc42b3d 2600/ unlim   -   root

 

SRX " B"

r@odc> show security ipsec security-associations    
  Total active tunnels: 2
  ID    Algorithm       SPI      Life:sec/kb  Mon lsys Port  Gateway   
  <131074 ESP:3des/sha1 f7739ba9 1910/ unlim   -   root 500   x.x.x.x  
  >131074 ESP:3des/sha1 483b1754 1910/ unlim   -   root 500   x.x.x.x  
  <131073 ESP:3des/sha1 afc42b3d 2950/ unlim   -   root 500   y.y.y.y 
  >131073 ESP:3des/sha1 f9dfd727 2950/ unlim   -   root 500   y.y.y.y 

No traffic srx A 131074 to srx B 131073 though ipsec & ike are up

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-29-2018 09:30 PM

this one didn't work

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-30-2018 02:07 AM

from SRX A ... found traffic output going toward SRX B and no iput traffice , did ping in 1min interval , but at SRX B  both input traffice increasing where as output traffic goes up when i do ping.. so which is blocking ?

 

SRX A

 <131074 ESP:3des/sha1 c1d006a3 3362/ unlim   -   root 500   y.y.y.y
  >131074 ESP:3des/sha1 c3dedf6a 3362/ unlim   -   root 500   y.y.y.y

 

Logical interface st0.3 (Index 75) (SNMP ifIndex 535)
    Flags: Point-To-Point SNMP-Traps Encapsulation: Secure-Tunnel
    Input packets : 0
    Output packets: 252
    Security: Zone: us--vpn
    Protocol inet, MTU: 9192
      Flags: Sendbcast-pkt-to-re
      Addresses, Flags: Is-Preferred Is-Primary
        Destination: 10.11.11/24, Local: 10.11.11.12

 

  Logical interface st0.3 (Index 75) (SNMP ifIndex 535)
    Flags: Point-To-Point SNMP-Traps Encapsulation: Secure-Tunnel
    Input packets : 0
    Output packets: 328
    Security: Zone: us--vpn
    Protocol inet, MTU: 9192
      Flags: Sendbcast-pkt-to-re
      Addresses, Flags: Is-Preferred Is-Primary
        Destination: 10.11.11/24, Local: 10.11.11.12

 

Srx Site B"

  <131074 x.x.x.x 500   ESP:3des/sha1   c3dedf6a 2994/ unlim   -   root
  >131074 x.x.x.x 500   ESP:3des/sha1   c1d006a3 2994/ unlim   -   root

 

  Logical interface st0.3 (Index 72) (SNMP ifIndex 518)
    Flags: Point-To-Point SNMP-Traps Encapsulation: Secure-Tunnel
    Input packets : 7800
    Output packets: 242
    Security: Zone: vpn
    Protocol inet, MTU: 9192
      Flags: Sendbcast-pkt-to-re
      Addresses, Flags: Is-Preferred Is-Primary
        Destination: 10.11.11/24, Local: 10.11.11.11

 

  Logical interface st0.3 (Index 72) (SNMP ifIndex 518)
    Flags: Point-To-Point SNMP-Traps Encapsulation: Secure-Tunnel
    Input packets : 7800
    Output packets: 242
    Security: Zone: vpn
    Protocol inet, MTU: 9192
      Flags: Sendbcast-pkt-to-re
      Addresses, Flags: Is-Preferred Is-Primary
        Destination: 10.11.11/24, Local: 10.11.11.11

Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-30-2018 03:04 AM

Can you apply flow traces on both SRX?

 

 

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: srx to srx site-site vpn is up but no traffic

‎12-30-2018 07:38 AM

from srx B ( 131074 ) , i got these logs , since srx A side junos version is  JUNOS Software Release [10.3R2.11] so i didn't get any logs,
can you help me commands in srx A

Dec 30 22:16:55 22:16:55.436378:CID-0:RT:-jsf int check: plugin id 23, svc_req 0x0, impl mask 0x0. rc 4
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:-jsf int check: plugin id 26, svc_req 0x0, impl mask 0x0. rc 4
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:-jsf int check: plugin id 27, svc_req 0x0, impl mask 0x0. rc 2
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:-jsf int check: plugin id 28, svc_req 0x0, impl mask 0x0. rc 4
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:[JSF]Plugins(0x0, count 0) enabled for session = 140055540, impli mask(0xa), post_nat cnt 276688 svc req(0x0)
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:-jsf : no plugin interested for session 42949949648, free sess plugin info
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:flow_first_service_lookup(): natp(0x5bf46de8): app_id, 0(0).
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  service lookup identified service 0.
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  flow_first_final_check: in <.local..0>, out <ge-0/0/0.0>
                                        
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:flow_first_complete_session, pak_ptr: 0x5090ec98, nsp: 0x5bf46de8, in_tunnel: 0x0
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:construct v4 vector for nsp2
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  existing vector list 0x0-0x48682060.
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  Session (id:276688) created for first pak 0
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  flow_first_install_session======> 0x5bf46de8
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT: nsp 0x5bf46de8, nsp2 0x5bf46e68
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  make_nsp_ready_no_resolve()
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  route lookup: dest-ip 2.1.159.195 orig ifp .local..0 output_ifp .local..0 orig-zone 2 out-zone 2 vsd 0
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  route to 2.1.159.195
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:no need update ha
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:Installing c2s NP session wing
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:Installing s2c NP session wing
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:  flow got session.
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT: flow fast tcp/udp session id 276688
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT: vector bits 0x0 vector 0x48682060
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:mbuf 0x4468d980, exit nh 0xf0010
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT:flow_process_pkt_exception: Freeing lpak 0x5090ec98 associated with mbuf 0x4468d980
 
Dec 30 22:16:55 22:16:55.436378:CID-0:RT: ----- flow_process_pkt rc 0x0 (fp rc 0)
 
 
Dec 30 22:17:49 22:17:49.441703:CID-0:RT:jsf sess close notify
 
Dec 30 22:17:49 22:17:49.441703:CID-0:RT:flow_ipv4_del_flow: sess 271693, in hash 32
 
Dec 30 22:17:49 22:17:49.441703:CID-0:RT:flow_ipv4_del_flow: sess 271693, in hash 32
 
Dec 30 22:17:53 22:17:53.444155:CID-0:RT:jsf sess close notify
 
Dec 30 22:17:53 22:17:53.444155:CID-0:RT:flow_ipv4_del_flow: sess 276688, in hash 32
 
Dec 30 22:17:53 22:17:53.444155:CID-0:RT:flow_ipv4_del_flow: sess 276688, in hash 32