FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rkelly_FTNT
Staff
Staff
Article Id 193948

Description

 
This article describes how to enable or disable inspection of IPv4 and IPv6 ICMP traffic without affecting TCP and UDP traffic. In order for the inspection of asymmetric ICMP traffic to not affect TCP and UDP traffic, a pair of settings have been added that can enable/disable the inspection of ICMP traffic being routed asymmetrically for both IPv4 and IPv6.

 

Scope

 

FortiGate.


Solution

 
The syntax in the CLI for configuring the setting is:

IPv4
 
config system settings
set asymroute-icmp enable/disable
end
 
IPv6
 
config system settings
set asymroute6-icmp enable/disable
end