Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS 5500 Showing Invalid traffic "Could not associate packet to any connection"

I've been facing an invalid traffic issue with an XGS5500 (SFOS 19.5.2 MR-2-Build624) for a few days.
the connections of some PCs to a particular domain seem to work but then I start to log errors such as "Invalid traffic". The firewall rule is a simple LAN to Wan rule without any checks. At the same time other PCs access the same domain easily. If I change the IP of the affected PC then it starts working properly (the next day I revert to the old IP it works fine). And this is not  TCP conn. establishment idle timeout value problem.



This thread was automatically locked due to age.
  • This is usually not a problem; it means that firewall has already closed the connection and after that another packet comes in for the same connection. Firewall is then not able to associate this packet to an existing connection.

    In most cases under "System services -> Log settings" you can deselect invalid traffic to get rid of those messages.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • I wrote an recommended read about this:  Sophos Firewall: Invalid Traffic  

    __________________________________________________________________________________________________________________