Fortinet white logo
Fortinet white logo

CLI Reference

config system settings

config system settings

Configure VDOM settings.

config system settings
    Description: Configure VDOM settings.
    set comments {var-string}
    set opmode [nat|transparent]
    set http-external-dest [fortiweb|forticache]
    set firewall-session-dirty [check-all|check-new|...]
    set manageip {user}
    set gateway {ipv4-address}
    set ip {ipv4-classnet-host}
    set manageip6 {ipv6-prefix}
    set gateway6 {ipv6-address}
    set ip6 {ipv6-prefix}
    set device {string}
    set utf8-spam-tagging [enable|disable]
    set wccp-cache-engine [enable|disable]
    set wccp-local-route [enable|disable]
    set vpn-stats-log {option1}, {option2}, ...
    set vpn-stats-period {integer}
    set mac-ttl {integer}
    set fw-session-hairpin [enable|disable]
    set prp-trailer-action [enable|disable]
    set snat-hairpin-traffic [enable|disable]
    set dhcp-proxy [enable|disable]
    set dhcp-proxy-interface-select-method [auto|sdwan|...]
    set dhcp-proxy-interface {string}
    set dhcp-server-ip {user}
    set dhcp6-server-ip {user}
    set gui-default-policy-columns <name1>, <name2>, ...
    set link-down-access [enable|disable]
    set asymroute [enable|disable]
    set asymroute-icmp [enable|disable]
    set tcp-session-without-syn [enable|disable]
    set ses-denied-traffic [enable|disable]
    set strict-src-check [enable|disable]
    set allow-linkdown-path [enable|disable]
    set asymroute6 [enable|disable]
    set asymroute6-icmp [enable|disable]
    set sctp-session-without-init [enable|disable]
    set status [enable|disable]
    set allow-subnet-overlap [enable|disable]
    set deny-tcp-with-icmp [enable|disable]
    set discovered-device-timeout {integer}
    set email-portal-check-dns [disable|enable]
    set gui-icap [enable|disable]
    set gui-implicit-policy [enable|disable]
    set gui-dns-database [enable|disable]
    set gui-multicast-policy [enable|disable]
    set gui-dos-policy [enable|disable]
    set gui-object-colors [enable|disable]
    set gui-voip-profile [enable|disable]
    set gui-security-profile-group [enable|disable]
    set gui-local-reports [enable|disable]
    set gui-wanopt-cache [enable|disable]
    set gui-explicit-proxy [enable|disable]
    set gui-policy-based-ipsec [enable|disable]
    set gui-threat-weight [enable|disable]
    set gui-spamfilter [enable|disable]
    set gui-file-filter [enable|disable]
    set gui-application-control [enable|disable]
    set gui-ips [enable|disable]
    set gui-endpoint-control [enable|disable]
    set gui-endpoint-control-advanced [enable|disable]
    set gui-dhcp-advanced [enable|disable]
    set gui-vpn [enable|disable]
    set gui-webfilter-advanced [enable|disable]
    set gui-traffic-shaping [enable|disable]
    set gui-antivirus [enable|disable]
    set gui-webfilter [enable|disable]
    set gui-videofilter [enable|disable]
    set gui-dnsfilter [enable|disable]
    set gui-advanced-policy [enable|disable]
    set gui-allow-unnamed-policy [enable|disable]
    set gui-email-collection [enable|disable]
    set gui-multiple-interface-policy [enable|disable]
    set gui-policy-disclaimer [enable|disable]
    set gui-ztna [enable|disable]
    set block-land-attack [disable|enable]
    set application-bandwidth-tracking [disable|enable]
end

config system settings

Parameter

Description

Type

Size

Default

comments

VDOM comments.

var-string

Maximum length: 255

opmode

Firewall operation mode (NAT or Transparent).

option

-

nat

Option

Description

nat

Change to NAT mode.

transparent

Change to transparent mode.

http-external-dest

Offload HTTP traffic to FortiWeb or FortiCache.

option

-

fortiweb

Option

Description

fortiweb

Offload HTTP traffic to FortiWeb for Web Application Firewall inspection.

forticache

Offload HTTP traffic to FortiCache for external web caching and WAN optimization.

firewall-session-dirty

Select how to manage sessions affected by firewall policy configuration changes.

option

-

check-all

Option

Description

check-all

All sessions affected by a firewall policy change are flushed from the session table. When new packets are recived they are re-evaluated by stateful inspection and re-added to the session table.

check-new

Estabished sessions for changed firewall policies continue without being affected by the policy configuration change. New sessions are evaluated according to the new firewall policy configuration.

check-policy-option

Sessions are managed individually depending on the firewall policy. Some sessions may restart. Some may continue.

manageip

Transparent mode IPv4 management IP address and netmask.

user

Not Specified

gateway

Transparent mode IPv4 default gateway IP address.

ipv4-address

Not Specified

0.0.0.0

ip

IP address and netmask.

ipv4-classnet-host

Not Specified

0.0.0.0 0.0.0.0

manageip6

Transparent mode IPv6 management IP address and netmask.

ipv6-prefix

Not Specified

::/0

gateway6

Transparent mode IPv4 default gateway IP address.

ipv6-address

Not Specified

::

ip6

IPv6 address prefix for NAT mode.

ipv6-prefix

Not Specified

::/0

device

Interface to use for management access for NAT mode.

string

Maximum length: 35

utf8-spam-tagging

Enable/disable converting antispam tags to UTF-8 for better non-ASCII character support.

option

-

enable

Option

Description

enable

Convert antispam tags to UTF-8.

disable

Do not convert antispam tags.

wccp-cache-engine

Enable/disable WCCP cache engine.

option

-

disable

Option

Description

enable

Enable WCCP cache engine.

disable

Disable WCCP cache engine.

wccp-local-route

Enable/disable WCCP to use local route.

option

-

disable

Option

Description

enable

Enable WCCP to use local route.

disable

Disable WCCP to use local route.

vpn-stats-log

Enable/disable periodic VPN log statistics for one or more types of VPN. Separate names with a space.

option

-

ipsec pptp l2tp

Option

Description

ipsec

IPsec.

pptp

PPTP.

l2tp

L2TP.

vpn-stats-period

Period to send VPN log statistics.

integer

Minimum value: 0 Maximum value: 4294967295

600

mac-ttl

Duration of MAC addresses in Transparent mode.

integer

Minimum value: 300 Maximum value: 8640000

300

fw-session-hairpin

Enable/disable checking for a matching policy each time hairpin traffic goes through the FortiProxy.

option

-

disable

Option

Description

enable

Perform a policy check every time.

disable

Perform a policy check only the first time the session is received.

prp-trailer-action

Enable/disable action to take on PRP trailer.

option

-

disable

Option

Description

enable

Try to keep PRP trailer.

disable

Trim PRP trailer.

snat-hairpin-traffic

Enable/disable source NAT (SNAT) for hairpin traffic.

option

-

enable

Option

Description

enable

Enable SNAT for hairpin traffic.

disable

Disable SNAT for hairpin traffic.

dhcp-proxy

Enable/disable the DHCP Proxy.

option

-

disable

Option

Description

enable

Enable the DHCP proxy.

disable

Disable the DHCP proxy.

dhcp-proxy-interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

sdwan

Set outgoing interface by SD-WAN or policy routing rules.

specify

Set outgoing interface manually.

dhcp-proxy-interface

Specify outgoing interface to reach server.

string

Maximum length: 15

dhcp-server-ip

DHCP Server IPv4 address.

user

Not Specified

dhcp6-server-ip

DHCPv6 server IPv6 address.

user

Not Specified

gui-default-policy-columns <name>

Default columns to display for policy lists on GUI.

Select column name.

string

Maximum length: 79

link-down-access

Enable/disable link down access traffic.

option

-

enable

Option

Description

enable

Allow link down access traffic.

disable

Block link down access traffic.

asymroute

Enable/disable IPv4 asymmetric routing.

option

-

disable

Option

Description

enable

Enable IPv4 asymmetric routing.

disable

Disable IPv4 asymmetric routing.

asymroute-icmp

Enable/disable ICMP asymmetric routing.

option

-

disable

Option

Description

enable

Enable ICMP asymmetric routing.

disable

Disable ICMP asymmetric routing.

tcp-session-without-syn

Enable/disable allowing TCP session without SYN flags.

option

-

disable

Option

Description

enable

Allow TCP session without SYN flags.

disable

Do not allow TCP session without SYN flags.

ses-denied-traffic

Enable/disable including denied session in the session table.

option

-

disable

Option

Description

enable

Include denied sessions in the session table.

disable

Do not add denied sessions to the session table.

strict-src-check

Enable/disable strict source verification.

option

-

disable

Option

Description

enable

Enable strict source verification.

disable

Disable strict source verification.

allow-linkdown-path

Enable/disable link down path.

option

-

disable

Option

Description

enable

Allow link down path.

disable

Do not allow link down path.

asymroute6

Enable/disable asymmetric IPv6 routing.

option

-

disable

Option

Description

enable

Enable asymmetric IPv6 routing.

disable

Disable asymmetric IPv6 routing.

asymroute6-icmp

Enable/disable asymmetric ICMPv6 routing.

option

-

disable

Option

Description

enable

Enable asymmetric ICMPv6 routing.

disable

Disable asymmetric ICMPv6 routing.

sctp-session-without-init

Enable/disable SCTP session creation without SCTP INIT.

option

-

disable

Option

Description

enable

Enable SCTP session creation without SCTP INIT.

disable

Disable SCTP session creation without SCTP INIT.

status

Enable/disable this VDOM.

option

-

enable

Option

Description

enable

Enable this VDOM.

disable

Disable this VDOM.

allow-subnet-overlap

Enable/disable allowing interface subnets to use overlapping IP addresses.

option

-

disable

Option

Description

enable

Enable overlapping subnets.

disable

Disable overlapping subnets.

deny-tcp-with-icmp

Enable/disable denying TCP by sending an ICMP communication prohibited packet.

option

-

disable

Option

Description

enable

Deny TCP with ICMP.

disable

Disable denying TCP with ICMP.

discovered-device-timeout

Timeout for discovered devices.

integer

Minimum value: 1 Maximum value: 365

28

email-portal-check-dns

Enable/disable using DNS to validate email addresses collected by a captive portal.

option

-

enable

Option

Description

disable

Disable email address checking with DNS.

enable

Enable email address checking with DNS.

gui-icap

Enable/disable ICAP on the GUI.

option

-

enable

Option

Description

enable

Enable ICAP on the GUI.

disable

Disable ICAP on the GUI.

gui-implicit-policy

Enable/disable implicit firewall policies on the GUI.

option

-

enable

Option

Description

enable

Enable implicit firewall policies on the GUI.

disable

Disable implicit firewall policies on the GUI.

gui-dns-database

Enable/disable DNS database settings on the GUI.

option

-

disable

Option

Description

enable

Enable DNS database settings on the GUI.

disable

Disable DNS database settings on the GUI.

gui-multicast-policy

Enable/disable multicast firewall policies on the GUI.

option

-

disable

Option

Description

enable

Enable multicast firewall policies on the GUI.

disable

Disable multicast firewall policies on the GUI.

gui-dos-policy

Enable/disable DoS policies on the GUI.

option

-

disable

Option

Description

enable

Enable DoS policies on the GUI.

disable

Disable DoS policies on the GUI.

gui-object-colors

Enable/disable object colors on the GUI.

option

-

enable

Option

Description

enable

Enable object colors on the GUI.

disable

Disable object colors on the GUI.

gui-voip-profile

Enable/disable VoIP profiles on the GUI.

option

-

disable

Option

Description

enable

Enable VoIP profiles on the GUI.

disable

Disable VoIP profiles on the GUI.

gui-security-profile-group

Enable/disable Security Profile Groups on the GUI.

option

-

disable

Option

Description

enable

Enable Security Profile Groups on the GUI.

disable

Disable Security Profile Groups on the GUI.

gui-local-reports

Enable/disable local reports on the GUI.

option

-

disable

Option

Description

enable

Enable local reports on the GUI.

disable

Disable local reports on the GUI.

gui-wanopt-cache

Enable/disable WAN Optimization and Web Caching on the GUI.

option

-

enable

Option

Description

enable

Enable WAN Optimization and Web Caching on the GUI.

disable

Disable WAN Optimization and Web Caching on the GUI.

gui-explicit-proxy

Enable/disable the explicit proxy on the GUI.

option

-

enable

Option

Description

enable

Enable the explicit proxy on the GUI.

disable

Disable the explicit proxy on the GUI.

gui-policy-based-ipsec

Enable/disable policy-based IPsec VPN on the GUI.

option

-

disable

Option

Description

enable

Enable policy-based IPsec VPN on the GUI.

disable

Disable policy-based IPsec VPN on the GUI.

gui-threat-weight

Enable/disable threat weight on the GUI.

option

-

enable

Option

Description

enable

Enable threat weight on the GUI.

disable

Disable threat weight on the GUI.

gui-spamfilter

Enable/disable Antispam on the GUI.

option

-

disable

Option

Description

enable

Enable Antispam on the GUI.

disable

Disable Antispam on the GUI.

gui-file-filter

Enable/disable File-filter on the GUI.

option

-

enable

Option

Description

enable

Enable File-filter on the GUI.

disable

Disable File-filter on the GUI.

gui-application-control

Enable/disable application control on the GUI.

option

-

enable

Option

Description

enable

Enable application control on the GUI.

disable

Disable application control on the GUI.

gui-ips

Enable/disable IPS on the GUI.

option

-

enable

Option

Description

enable

Enable IPS on the GUI.

disable

Disable IPS on the GUI.

gui-endpoint-control

Enable/disable endpoint control on the GUI.

option

-

disable

Option

Description

enable

Enable endpoint control on the GUI.

disable

Disable endpoint control on the GUI.

gui-endpoint-control-advanced

Enable/disable advanced endpoint control options on the GUI.

option

-

disable

Option

Description

enable

Enable advanced endpoint control options on the GUI.

disable

Disable advanced endpoint control options on the GUI.

gui-dhcp-advanced

Enable/disable advanced DHCP options on the GUI.

option

-

enable

Option

Description

enable

Enable advanced DHCP options on the GUI.

disable

Disable advanced DHCP options on the GUI.

gui-vpn

Enable/disable VPN tunnels on the GUI.

option

-

enable

Option

Description

enable

Enable VPN tunnels on the GUI.

disable

Disable VPN tunnels on the GUI.

gui-webfilter-advanced

Enable/disable advanced web filtering on the GUI.

option

-

enable

Option

Description

enable

Enable advanced web filtering on the GUI.

disable

Disable advanced web filtering on the GUI.

gui-traffic-shaping

Enable/disable traffic shaping on the GUI.

option

-

enable

Option

Description

enable

Enable traffic shaping on the GUI.

disable

Disable traffic shaping on the GUI.

gui-antivirus

Enable/disable AntiVirus on the GUI.

option

-

enable

Option

Description

enable

Enable AntiVirus on the GUI.

disable

Disable AntiVirus on the GUI.

gui-webfilter

Enable/disable Web filtering on the GUI.

option

-

enable

Option

Description

enable

Enable Web filtering on the GUI.

disable

Disable Web filtering on the GUI.

gui-videofilter

Enable/disable Video filtering on the GUI.

option

-

enable

Option

Description

enable

Enable Video filtering on the GUI.

disable

Disable Video filtering on the GUI.

gui-dnsfilter

Enable/disable DNS Filtering on the GUI.

option

-

enable

Option

Description

enable

Enable DNS Filtering on the GUI.

disable

Disable DNS Filtering on the GUI.

gui-advanced-policy

Enable/disable advanced policy configuration on the GUI.

option

-

disable

Option

Description

enable

Enable advanced policy configuration on the GUI.

disable

Disable advanced policy configuration on the GUI.

gui-allow-unnamed-policy

Enable/disable the requirement for policy naming on the GUI.

option

-

enable

Option

Description

enable

Enable the requirement for policy naming on the GUI.

disable

Disable the requirement for policy naming on the GUI.

gui-email-collection

Enable/disable email collection on the GUI.

option

-

disable

Option

Description

enable

Enable email collection on the GUI.

disable

Disable email collection on the GUI.

gui-multiple-interface-policy

Enable/disable adding multiple interfaces to a policy on the GUI.

option

-

enable

Option

Description

enable

Enable adding multiple interfaces to a policy on the GUI.

disable

Disable adding multiple interfaces to a policy on the GUI.

gui-policy-disclaimer

Enable/disable policy disclaimer on the GUI.

option

-

disable

Option

Description

enable

Enable policy disclaimer on the GUI.

disable

Disable policy disclaimer on the GUI.

gui-ztna

Enable/disable Zero Trust Network Access features on the GUI.

option

-

enable

Option

Description

enable

Enable Zero Trust Network Access features on the GUI.

disable

Disable Zero Trust Network Access features on the GUI.

block-land-attack

Enable/disable blocking of land attacks.

option

-

disable

Option

Description

disable

Do not block land attack.

enable

Block land attack.

application-bandwidth-tracking

Enable/disable application bandwidth tracking.

option

-

disable

Option

Description

disable

Disable application bandwidth tracking.

enable

Enable application bandwidth tracking.

config system settings

config system settings

Configure VDOM settings.

config system settings
    Description: Configure VDOM settings.
    set comments {var-string}
    set opmode [nat|transparent]
    set http-external-dest [fortiweb|forticache]
    set firewall-session-dirty [check-all|check-new|...]
    set manageip {user}
    set gateway {ipv4-address}
    set ip {ipv4-classnet-host}
    set manageip6 {ipv6-prefix}
    set gateway6 {ipv6-address}
    set ip6 {ipv6-prefix}
    set device {string}
    set utf8-spam-tagging [enable|disable]
    set wccp-cache-engine [enable|disable]
    set wccp-local-route [enable|disable]
    set vpn-stats-log {option1}, {option2}, ...
    set vpn-stats-period {integer}
    set mac-ttl {integer}
    set fw-session-hairpin [enable|disable]
    set prp-trailer-action [enable|disable]
    set snat-hairpin-traffic [enable|disable]
    set dhcp-proxy [enable|disable]
    set dhcp-proxy-interface-select-method [auto|sdwan|...]
    set dhcp-proxy-interface {string}
    set dhcp-server-ip {user}
    set dhcp6-server-ip {user}
    set gui-default-policy-columns <name1>, <name2>, ...
    set link-down-access [enable|disable]
    set asymroute [enable|disable]
    set asymroute-icmp [enable|disable]
    set tcp-session-without-syn [enable|disable]
    set ses-denied-traffic [enable|disable]
    set strict-src-check [enable|disable]
    set allow-linkdown-path [enable|disable]
    set asymroute6 [enable|disable]
    set asymroute6-icmp [enable|disable]
    set sctp-session-without-init [enable|disable]
    set status [enable|disable]
    set allow-subnet-overlap [enable|disable]
    set deny-tcp-with-icmp [enable|disable]
    set discovered-device-timeout {integer}
    set email-portal-check-dns [disable|enable]
    set gui-icap [enable|disable]
    set gui-implicit-policy [enable|disable]
    set gui-dns-database [enable|disable]
    set gui-multicast-policy [enable|disable]
    set gui-dos-policy [enable|disable]
    set gui-object-colors [enable|disable]
    set gui-voip-profile [enable|disable]
    set gui-security-profile-group [enable|disable]
    set gui-local-reports [enable|disable]
    set gui-wanopt-cache [enable|disable]
    set gui-explicit-proxy [enable|disable]
    set gui-policy-based-ipsec [enable|disable]
    set gui-threat-weight [enable|disable]
    set gui-spamfilter [enable|disable]
    set gui-file-filter [enable|disable]
    set gui-application-control [enable|disable]
    set gui-ips [enable|disable]
    set gui-endpoint-control [enable|disable]
    set gui-endpoint-control-advanced [enable|disable]
    set gui-dhcp-advanced [enable|disable]
    set gui-vpn [enable|disable]
    set gui-webfilter-advanced [enable|disable]
    set gui-traffic-shaping [enable|disable]
    set gui-antivirus [enable|disable]
    set gui-webfilter [enable|disable]
    set gui-videofilter [enable|disable]
    set gui-dnsfilter [enable|disable]
    set gui-advanced-policy [enable|disable]
    set gui-allow-unnamed-policy [enable|disable]
    set gui-email-collection [enable|disable]
    set gui-multiple-interface-policy [enable|disable]
    set gui-policy-disclaimer [enable|disable]
    set gui-ztna [enable|disable]
    set block-land-attack [disable|enable]
    set application-bandwidth-tracking [disable|enable]
end

config system settings

Parameter

Description

Type

Size

Default

comments

VDOM comments.

var-string

Maximum length: 255

opmode

Firewall operation mode (NAT or Transparent).

option

-

nat

Option

Description

nat

Change to NAT mode.

transparent

Change to transparent mode.

http-external-dest

Offload HTTP traffic to FortiWeb or FortiCache.

option

-

fortiweb

Option

Description

fortiweb

Offload HTTP traffic to FortiWeb for Web Application Firewall inspection.

forticache

Offload HTTP traffic to FortiCache for external web caching and WAN optimization.

firewall-session-dirty

Select how to manage sessions affected by firewall policy configuration changes.

option

-

check-all

Option

Description

check-all

All sessions affected by a firewall policy change are flushed from the session table. When new packets are recived they are re-evaluated by stateful inspection and re-added to the session table.

check-new

Estabished sessions for changed firewall policies continue without being affected by the policy configuration change. New sessions are evaluated according to the new firewall policy configuration.

check-policy-option

Sessions are managed individually depending on the firewall policy. Some sessions may restart. Some may continue.

manageip

Transparent mode IPv4 management IP address and netmask.

user

Not Specified

gateway

Transparent mode IPv4 default gateway IP address.

ipv4-address

Not Specified

0.0.0.0

ip

IP address and netmask.

ipv4-classnet-host

Not Specified

0.0.0.0 0.0.0.0

manageip6

Transparent mode IPv6 management IP address and netmask.

ipv6-prefix

Not Specified

::/0

gateway6

Transparent mode IPv4 default gateway IP address.

ipv6-address

Not Specified

::

ip6

IPv6 address prefix for NAT mode.

ipv6-prefix

Not Specified

::/0

device

Interface to use for management access for NAT mode.

string

Maximum length: 35

utf8-spam-tagging

Enable/disable converting antispam tags to UTF-8 for better non-ASCII character support.

option

-

enable

Option

Description

enable

Convert antispam tags to UTF-8.

disable

Do not convert antispam tags.

wccp-cache-engine

Enable/disable WCCP cache engine.

option

-

disable

Option

Description

enable

Enable WCCP cache engine.

disable

Disable WCCP cache engine.

wccp-local-route

Enable/disable WCCP to use local route.

option

-

disable

Option

Description

enable

Enable WCCP to use local route.

disable

Disable WCCP to use local route.

vpn-stats-log

Enable/disable periodic VPN log statistics for one or more types of VPN. Separate names with a space.

option

-

ipsec pptp l2tp

Option

Description

ipsec

IPsec.

pptp

PPTP.

l2tp

L2TP.

vpn-stats-period

Period to send VPN log statistics.

integer

Minimum value: 0 Maximum value: 4294967295

600

mac-ttl

Duration of MAC addresses in Transparent mode.

integer

Minimum value: 300 Maximum value: 8640000

300

fw-session-hairpin

Enable/disable checking for a matching policy each time hairpin traffic goes through the FortiProxy.

option

-

disable

Option

Description

enable

Perform a policy check every time.

disable

Perform a policy check only the first time the session is received.

prp-trailer-action

Enable/disable action to take on PRP trailer.

option

-

disable

Option

Description

enable

Try to keep PRP trailer.

disable

Trim PRP trailer.

snat-hairpin-traffic

Enable/disable source NAT (SNAT) for hairpin traffic.

option

-

enable

Option

Description

enable

Enable SNAT for hairpin traffic.

disable

Disable SNAT for hairpin traffic.

dhcp-proxy

Enable/disable the DHCP Proxy.

option

-

disable

Option

Description

enable

Enable the DHCP proxy.

disable

Disable the DHCP proxy.

dhcp-proxy-interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

sdwan

Set outgoing interface by SD-WAN or policy routing rules.

specify

Set outgoing interface manually.

dhcp-proxy-interface

Specify outgoing interface to reach server.

string

Maximum length: 15

dhcp-server-ip

DHCP Server IPv4 address.

user

Not Specified

dhcp6-server-ip

DHCPv6 server IPv6 address.

user

Not Specified

gui-default-policy-columns <name>

Default columns to display for policy lists on GUI.

Select column name.

string

Maximum length: 79

link-down-access

Enable/disable link down access traffic.

option

-

enable

Option

Description

enable

Allow link down access traffic.

disable

Block link down access traffic.

asymroute

Enable/disable IPv4 asymmetric routing.

option

-

disable

Option

Description

enable

Enable IPv4 asymmetric routing.

disable

Disable IPv4 asymmetric routing.

asymroute-icmp

Enable/disable ICMP asymmetric routing.

option

-

disable

Option

Description

enable

Enable ICMP asymmetric routing.

disable

Disable ICMP asymmetric routing.

tcp-session-without-syn

Enable/disable allowing TCP session without SYN flags.

option

-

disable

Option

Description

enable

Allow TCP session without SYN flags.

disable

Do not allow TCP session without SYN flags.

ses-denied-traffic

Enable/disable including denied session in the session table.

option

-

disable

Option

Description

enable

Include denied sessions in the session table.

disable

Do not add denied sessions to the session table.

strict-src-check

Enable/disable strict source verification.

option

-

disable

Option

Description

enable

Enable strict source verification.

disable

Disable strict source verification.

allow-linkdown-path

Enable/disable link down path.

option

-

disable

Option

Description

enable

Allow link down path.

disable

Do not allow link down path.

asymroute6

Enable/disable asymmetric IPv6 routing.

option

-

disable

Option

Description

enable

Enable asymmetric IPv6 routing.

disable

Disable asymmetric IPv6 routing.

asymroute6-icmp

Enable/disable asymmetric ICMPv6 routing.

option

-

disable

Option

Description

enable

Enable asymmetric ICMPv6 routing.

disable

Disable asymmetric ICMPv6 routing.

sctp-session-without-init

Enable/disable SCTP session creation without SCTP INIT.

option

-

disable

Option

Description

enable

Enable SCTP session creation without SCTP INIT.

disable

Disable SCTP session creation without SCTP INIT.

status

Enable/disable this VDOM.

option

-

enable

Option

Description

enable

Enable this VDOM.

disable

Disable this VDOM.

allow-subnet-overlap

Enable/disable allowing interface subnets to use overlapping IP addresses.

option

-

disable

Option

Description

enable

Enable overlapping subnets.

disable

Disable overlapping subnets.

deny-tcp-with-icmp

Enable/disable denying TCP by sending an ICMP communication prohibited packet.

option

-

disable

Option

Description

enable

Deny TCP with ICMP.

disable

Disable denying TCP with ICMP.

discovered-device-timeout

Timeout for discovered devices.

integer

Minimum value: 1 Maximum value: 365

28

email-portal-check-dns

Enable/disable using DNS to validate email addresses collected by a captive portal.

option

-

enable

Option

Description

disable

Disable email address checking with DNS.

enable

Enable email address checking with DNS.

gui-icap

Enable/disable ICAP on the GUI.

option

-

enable

Option

Description

enable

Enable ICAP on the GUI.

disable

Disable ICAP on the GUI.

gui-implicit-policy

Enable/disable implicit firewall policies on the GUI.

option

-

enable

Option

Description

enable

Enable implicit firewall policies on the GUI.

disable

Disable implicit firewall policies on the GUI.

gui-dns-database

Enable/disable DNS database settings on the GUI.

option

-

disable

Option

Description

enable

Enable DNS database settings on the GUI.

disable

Disable DNS database settings on the GUI.

gui-multicast-policy

Enable/disable multicast firewall policies on the GUI.

option

-

disable

Option

Description

enable

Enable multicast firewall policies on the GUI.

disable

Disable multicast firewall policies on the GUI.

gui-dos-policy

Enable/disable DoS policies on the GUI.

option

-

disable

Option

Description

enable

Enable DoS policies on the GUI.

disable

Disable DoS policies on the GUI.

gui-object-colors

Enable/disable object colors on the GUI.

option

-

enable

Option

Description

enable

Enable object colors on the GUI.

disable

Disable object colors on the GUI.

gui-voip-profile

Enable/disable VoIP profiles on the GUI.

option

-

disable

Option

Description

enable

Enable VoIP profiles on the GUI.

disable

Disable VoIP profiles on the GUI.

gui-security-profile-group

Enable/disable Security Profile Groups on the GUI.

option

-

disable

Option

Description

enable

Enable Security Profile Groups on the GUI.

disable

Disable Security Profile Groups on the GUI.

gui-local-reports

Enable/disable local reports on the GUI.

option

-

disable

Option

Description

enable

Enable local reports on the GUI.

disable

Disable local reports on the GUI.

gui-wanopt-cache

Enable/disable WAN Optimization and Web Caching on the GUI.

option

-

enable

Option

Description

enable

Enable WAN Optimization and Web Caching on the GUI.

disable

Disable WAN Optimization and Web Caching on the GUI.

gui-explicit-proxy

Enable/disable the explicit proxy on the GUI.

option

-

enable

Option

Description

enable

Enable the explicit proxy on the GUI.

disable

Disable the explicit proxy on the GUI.

gui-policy-based-ipsec

Enable/disable policy-based IPsec VPN on the GUI.

option

-

disable

Option

Description

enable

Enable policy-based IPsec VPN on the GUI.

disable

Disable policy-based IPsec VPN on the GUI.

gui-threat-weight

Enable/disable threat weight on the GUI.

option

-

enable

Option

Description

enable

Enable threat weight on the GUI.

disable

Disable threat weight on the GUI.

gui-spamfilter

Enable/disable Antispam on the GUI.

option

-

disable

Option

Description

enable

Enable Antispam on the GUI.

disable

Disable Antispam on the GUI.

gui-file-filter

Enable/disable File-filter on the GUI.

option

-

enable

Option

Description

enable

Enable File-filter on the GUI.

disable

Disable File-filter on the GUI.

gui-application-control

Enable/disable application control on the GUI.

option

-

enable

Option

Description

enable

Enable application control on the GUI.

disable

Disable application control on the GUI.

gui-ips

Enable/disable IPS on the GUI.

option

-

enable

Option

Description

enable

Enable IPS on the GUI.

disable

Disable IPS on the GUI.

gui-endpoint-control

Enable/disable endpoint control on the GUI.

option

-

disable

Option

Description

enable

Enable endpoint control on the GUI.

disable

Disable endpoint control on the GUI.

gui-endpoint-control-advanced

Enable/disable advanced endpoint control options on the GUI.

option

-

disable

Option

Description

enable

Enable advanced endpoint control options on the GUI.

disable

Disable advanced endpoint control options on the GUI.

gui-dhcp-advanced

Enable/disable advanced DHCP options on the GUI.

option

-

enable

Option

Description

enable

Enable advanced DHCP options on the GUI.

disable

Disable advanced DHCP options on the GUI.

gui-vpn

Enable/disable VPN tunnels on the GUI.

option

-

enable

Option

Description

enable

Enable VPN tunnels on the GUI.

disable

Disable VPN tunnels on the GUI.

gui-webfilter-advanced

Enable/disable advanced web filtering on the GUI.

option

-

enable

Option

Description

enable

Enable advanced web filtering on the GUI.

disable

Disable advanced web filtering on the GUI.

gui-traffic-shaping

Enable/disable traffic shaping on the GUI.

option

-

enable

Option

Description

enable

Enable traffic shaping on the GUI.

disable

Disable traffic shaping on the GUI.

gui-antivirus

Enable/disable AntiVirus on the GUI.

option

-

enable

Option

Description

enable

Enable AntiVirus on the GUI.

disable

Disable AntiVirus on the GUI.

gui-webfilter

Enable/disable Web filtering on the GUI.

option

-

enable

Option

Description

enable

Enable Web filtering on the GUI.

disable

Disable Web filtering on the GUI.

gui-videofilter

Enable/disable Video filtering on the GUI.

option

-

enable

Option

Description

enable

Enable Video filtering on the GUI.

disable

Disable Video filtering on the GUI.

gui-dnsfilter

Enable/disable DNS Filtering on the GUI.

option

-

enable

Option

Description

enable

Enable DNS Filtering on the GUI.

disable

Disable DNS Filtering on the GUI.

gui-advanced-policy

Enable/disable advanced policy configuration on the GUI.

option

-

disable

Option

Description

enable

Enable advanced policy configuration on the GUI.

disable

Disable advanced policy configuration on the GUI.

gui-allow-unnamed-policy

Enable/disable the requirement for policy naming on the GUI.

option

-

enable

Option

Description

enable

Enable the requirement for policy naming on the GUI.

disable

Disable the requirement for policy naming on the GUI.

gui-email-collection

Enable/disable email collection on the GUI.

option

-

disable

Option

Description

enable

Enable email collection on the GUI.

disable

Disable email collection on the GUI.

gui-multiple-interface-policy

Enable/disable adding multiple interfaces to a policy on the GUI.

option

-

enable

Option

Description

enable

Enable adding multiple interfaces to a policy on the GUI.

disable

Disable adding multiple interfaces to a policy on the GUI.

gui-policy-disclaimer

Enable/disable policy disclaimer on the GUI.

option

-

disable

Option

Description

enable

Enable policy disclaimer on the GUI.

disable

Disable policy disclaimer on the GUI.

gui-ztna

Enable/disable Zero Trust Network Access features on the GUI.

option

-

enable

Option

Description

enable

Enable Zero Trust Network Access features on the GUI.

disable

Disable Zero Trust Network Access features on the GUI.

block-land-attack

Enable/disable blocking of land attacks.

option

-

disable

Option

Description

disable

Do not block land attack.

enable

Block land attack.

application-bandwidth-tracking

Enable/disable application bandwidth tracking.

option

-

disable

Option

Description

disable

Disable application bandwidth tracking.

enable

Enable application bandwidth tracking.