FortiGate-ASM-FB4 Version 1.0 Technical Note
14
01-30005-0424-20071002
config system interface
Specialized CLI settings
Variables
Description
Default
mediatype {serdes
| sgmii}
Select the media type of the transceiver.
serdes
fp-anomaly
{drop_icmpland |
pass_icmpland}
{drop_ipland |
pass_ipland}
{drop_iplsrr |
pass_iplsrr}
{drop_iprr |
pass_iprr}
{drop_ipsecurity
|
pass_ipsecurity}
{drop_ipssrr |
pass_ipssrr}
{drop_ipstream |
pass_ipstream}
{drop_iptimestamp
|
pass_iptimestamp}
{drop_ipunknown_o
ption |
pass_ipunknown_op
tion}
{drop_unknown_pro
t |
pass_ipunknown_pr
ot} {drop_tcpland
| pass_tcpland}
{drop_udpland |
pass_udpland}
{drop_winnuke |
pass_winnuke}
By configuring this option, enable hardware
anomaly checking, and list whether to drop or
allow (pass) specific anomaly types.
•
drop_icmpland
: Drop ICMP land.
•
pass_icmpland
: Allow ICMP land to pass.
•
drop_ipland
: Drop IP land.
•
pass_ipland
: Allow IP land to pass.
•
drop_iplsrr
: Drop IP with loose source
record route option.
•
pass_iplsrr
: Allow IP with loose source
record route option to pass.
•
drop_iprr
: Drop IP with record route option.
•
pass_iprr
: Allow IP with record route option
to pass.
•
drop_ipsecurity
: Drop IP with security
option.
•
pass_ipsecurity
: Allow IP with security
option to pass.
•
drop_ipssrr
: Drop IP with strict source
record route option.
•
pass_ipssrr
: Allow IP with strict source
record route option to pass.
•
drop_ipstream
: Drop IP with stream option.
•
pass_ipstream
: Allow IP with stream option
to pass.
•
drop_iptimestamp
: Drop IP with timestamp
option.
•
pass_iptimestamp
: Allow IP with timestamp
option to pass.
•
drop_ipunknown_option
: Drop IP with
unknown option.
•
pass_ipunknown_option
: Allow IP with
unknown option to pass.
•
drop_ipunknown_prot
: Drop IP with
unknown protocol.
•
pass_ipunknown_prot
: Allow IP with
unknown protocol to pass.
•
drop_tcpland
: Drop TCP land.
•
pass_tcpland
: Allow TCP land to pass.
•
drop_winnuke
: Drop TCP WinNuke.
•
pass_winnuke
: Allow TCP WinNuke to pass.
•
drop_udpland
: Drop UDP land.
•
pass_udpland
: Allow UDP land to pass.
Separate each anomaly’s option with a space. To
add or remove an option from the list, completely
retype the new list.
When no options are specified, anomaly checking
performed by the FortiGate-ASM-FB4 module is
disabled. If pass options are specified, packets
may still be rejected by other anomaly checks,
including policy-required IPS performed using the
FortiGate unit’s main processing resources.
Log messages are generated when packets are
dropped due to options in this setting.
No options
specified
(disabled)