ICMP Profile
Use the ICMP Profile to configure various ICMP parameters.
Use a single ICMP Profile for all SPPs unless you need specialized ACLs.
All ICMP Profile parameters can be used with symmetric or asymmetric traffic
You can create a maximum of 64 ICMP Profiles.
Field/Selection |
Description |
Recommendations (For Web Servers, Firewalls, DNS Servers) |
---|---|---|
Name | 1-35 characters (a-Z, 0-9, "-", "_" only) |
|
ICMP Strict Anomalies |
Drops ICMP Checksum Error, missing payload and other ICMP header anomalies. |
Recommended enabled for all SPPs. |
ICMP Type Code Anomaly | Drops ICMP Type/Code packets where the Type/Code is not ratified by IETF/IANA. Note, less than 200 of the possible 65,536 Type/Code possibilities are ratified. FortiDDoS sets Thresholds for all 65,536 Type/Codes and will mitigate without the ACL but this will drop even single non-ratified packets. | Recommended enabled for all SPPs unless substantial IPv6 traffic. New IPv6 Types/Codes are being added frequently. If you are using substantial IPv6, use the existing ICMP Type/Code Thresholds. |
ICMP Type Code ACL |
Enable to create ICMP Type Code ACLs. |
Expert use
|
|
1-35 characters (a-Z, 0-9, "-", "_" only) |
|
|
0-255 |
|
|
0-255 |
|
|
0-255 |
|
|
0-255 |
|
|
Select either or both ICMP (v4 - Protocol 1) or ICMPv6 (Protocol 58) |