config system np6xlite
This command is available for model(s): FortiGate 100F, FortiGate 101F, FortiGate 200F, FortiGate 201F, FortiGate 40F 3G4G, FortiGate 40F, FortiGate 60F, FortiGate 61F, FortiGate 70F, FortiGate 71F, FortiGate 80F Bypass, FortiGate 80F DSL, FortiGate 80F-POE, FortiGate 80F, FortiGate 81F, FortiGateRugged 60F 3G4G, FortiGateRugged 60F, FortiGateRugged 70F 3G4G, FortiGateRugged 70F, FortiWiFi 40F 3G4G, FortiWiFi 40F, FortiWiFi 60F, FortiWiFi 61F, FortiWiFi 80F 2R 3G4G DSL, FortiWiFi 80F 2R, FortiWiFi 81F 2R 3G4G DSL, FortiWiFi 81F 2R 3G4G-POE, FortiWiFi 81F 2R-POE, FortiWiFi 81F 2R. It is not available for: FortiGate 1000D, FortiGate 1000F, FortiGate 1001F, FortiGate 1100E, FortiGate 1101E, FortiGate 120G, FortiGate 121G, FortiGate 1800F, FortiGate 1801F, FortiGate 2000E, FortiGate 200E, FortiGate 201E, FortiGate 2200E, FortiGate 2201E, FortiGate 2500E, FortiGate 2600F, FortiGate 2601F, FortiGate 3000D, FortiGate 3000F, FortiGate 3001F, FortiGate 300E, FortiGate 301E, FortiGate 3100D, FortiGate 3200D, FortiGate 3200F, FortiGate 3201F, FortiGate 3300E, FortiGate 3301E, FortiGate 3400E, FortiGate 3401E, FortiGate 3500F, FortiGate 3501F, FortiGate 3600E, FortiGate 3601E, FortiGate 3700D, FortiGate 3700F, FortiGate 3701F, FortiGate 3960E, FortiGate 3980E, FortiGate 400E Bypass, FortiGate 400E, FortiGate 400F, FortiGate 401E, FortiGate 401F, FortiGate 4200F, FortiGate 4201F, FortiGate 4400F, FortiGate 4401F, FortiGate 5001E1, FortiGate 5001E, FortiGate 500E, FortiGate 501E, FortiGate 600E, FortiGate 600F, FortiGate 601E, FortiGate 601F, FortiGate 800D, FortiGate 900D, FortiGate 900G, FortiGate 901G, FortiGate 90G, FortiGate 91G, FortiGate VM ARM64 for Azure, FortiGate VM ARM64 for GCP BYOL, FortiGate VM ARM64 for OCI BYOL, FortiGate VM for Aliyun PAYG, FortiGate VM for AWS PAYG, FortiGate VM for Azure BYOL, FortiGate VM for Azure PAYG, FortiGate VM for GCP BYOL, FortiGate VM for OPC BYOL, FortiGate VM64. |
Configure NP6XLITE attributes.
config system np6xlite Description: Configure NP6XLITE attributes. edit <name> set congestion-handling-mode [flow-control|head-of-line] set fastpath [disable|enable] config fp-anomaly Description: NP6XLITE IPv4 anomaly protection. The trap-to-host forwards anomaly sessions to the CPU. set icmp-csum-err [drop|trap-to-host] set icmp-frag [allow|drop|...] set icmp-land [allow|drop|...] set ipv4-csum-err [drop|trap-to-host] set ipv4-land [allow|drop|...] set ipv4-optlsrr [allow|drop|...] set ipv4-optrr [allow|drop|...] set ipv4-optsecurity [allow|drop|...] set ipv4-optssrr [allow|drop|...] set ipv4-optstream [allow|drop|...] set ipv4-opttimestamp [allow|drop|...] set ipv4-proto-err [allow|drop|...] set ipv4-unknopt [allow|drop|...] set ipv6-daddr-err [allow|drop|...] set ipv6-land [allow|drop|...] set ipv6-optendpid [allow|drop|...] set ipv6-opthomeaddr [allow|drop|...] set ipv6-optinvld [allow|drop|...] set ipv6-optjumbo [allow|drop|...] set ipv6-optnsap [allow|drop|...] set ipv6-optralert [allow|drop|...] set ipv6-opttunnel [allow|drop|...] set ipv6-proto-err [allow|drop|...] set ipv6-saddr-err [allow|drop|...] set ipv6-unknopt [allow|drop|...] set tcp-csum-err [drop|trap-to-host] set tcp-fin-noack [allow|drop|...] set tcp-fin-only [allow|drop|...] set tcp-land [allow|drop|...] set tcp-no-flag [allow|drop|...] set tcp-syn-data [allow|drop|...] set tcp-syn-fin [allow|drop|...] set tcp-winnuke [allow|drop|...] set udp-csum-err [drop|trap-to-host] set udp-land [allow|drop|...] end config hpe Description: HPE configuration. set arp-max {integer} set enable-shaper [disable|enable] set esp-max {integer} set icmp-max {integer} set ip-frag-max {integer} set ip-others-max {integer} set l2-others-max {integer} set pri-type-max {integer} set sctp-max {integer} set tcp-others-max {integer} set tcpfin-rst-max {integer} set tcpsyn-ack-max {integer} set tcpsyn-max {integer} set udp-max {integer} end set ipsec-inner-fragment [disable|enable] set ipsec-sts-timeout [1|2|...] set ipsec-throughput-msg-frequency [disable|32kb|...] set per-session-accounting [disable|traffic-log-only|...] set session-timeout-interval {integer} next end
config system np6xlite
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
congestion-handling-mode * |
Configure Marvell switch packet congestion handling. |
option |
- |
head-of-line |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
fastpath |
Enable/disable NP6XLITE offloading (also called fast path). |
option |
- |
enable |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
ipsec-inner-fragment |
Enable/disable NP6XLite IPsec fragmentation type: inner. |
option |
- |
disable |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
ipsec-sts-timeout |
Set NP6XLite IPsec STS message timeout. |
option |
- |
5 |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
ipsec-throughput-msg-frequency |
Set NP6XLite IPsec throughput message frequency (0 = disable). |
option |
- |
disable |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
name |
Device Name. |
string |
Maximum length: 31 |
|
||||||||||||||||||||||||||||||||||||
per-session-accounting |
Enable/disable per-session accounting. |
option |
- |
traffic-log-only |
||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
session-timeout-interval |
Set session timeout interval. |
integer |
Minimum value: 0 Maximum value: 1000 |
40 |
* This parameter may not exist in some models.
config fp-anomaly
Parameter |
Description |
Type |
Size |
Default |
||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
icmp-csum-err |
Invalid IPv4 ICMP checksum anomalies. |
option |
- |
drop |
||||||||
|
|
|||||||||||
icmp-frag |
Layer 3 fragmented packets that could be part of layer 4 ICMP anomalies. |
option |
- |
allow |
||||||||
|
|
|||||||||||
icmp-land |
ICMP land anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-csum-err |
Invalid IPv4 IP checksum anomalies. |
option |
- |
drop |
||||||||
|
|
|||||||||||
ipv4-land |
Land anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-optlsrr |
Loose source record route option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-optrr |
Record route option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-optsecurity |
Security option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-optssrr |
Strict source record route option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-optstream |
Stream option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-opttimestamp |
Timestamp option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-proto-err |
Invalid layer 4 protocol anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv4-unknopt |
Unknown option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-daddr-err |
Destination address as unspecified or loopback address anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-land |
Land anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-optendpid |
End point identification anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-opthomeaddr |
Home address option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-optinvld |
Invalid option anomalies.Invalid option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-optjumbo |
Jumbo options anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-optnsap |
Network service access point address option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-optralert |
Router alert option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-opttunnel |
Tunnel encapsulation limit option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-proto-err |
Layer 4 invalid protocol anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-saddr-err |
Source address as multicast anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
ipv6-unknopt |
Unknown option anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
tcp-csum-err |
Invalid IPv4 TCP checksum anomalies. |
option |
- |
drop |
||||||||
|
|
|||||||||||
tcp-fin-noack |
TCP SYN flood with FIN flag set without ACK setting anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
tcp-fin-only |
TCP SYN flood with only FIN flag set anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
tcp-land |
TCP land anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
tcp-no-flag |
TCP SYN flood with no flag set anomalies. |
option |
- |
allow |
||||||||
|
|
|||||||||||
tcp-syn-data |
TCP SYN flood packets with data anomalies. |
option |
- |
allow |
||||||||
|
|
|||||||||||
tcp-syn-fin |
TCP SYN flood SYN/FIN flag set anomalies. |
option |
- |
allow |
||||||||
|
|
|||||||||||
tcp-winnuke |
TCP WinNuke anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
|||||||||||
udp-csum-err |
Invalid IPv4 UDP checksum anomalies. |
option |
- |
drop |
||||||||
|
|
|||||||||||
udp-land |
UDP land anomalies. |
option |
- |
trap-to-host |
||||||||
|
|
config hpe
Parameter |
Description |
Type |
Size |
Default |
||||||
---|---|---|---|---|---|---|---|---|---|---|
arp-max |
Maximum ARP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
enable-shaper |
Enable/Disable NPU host protection engine (HPE) shaper. |
option |
- |
disable |
||||||
|
|
|||||||||
esp-max |
Maximum ESP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
icmp-max |
Maximum ICMP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
ip-frag-max |
Maximum fragmented IP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
ip-others-max |
Maximum IP packet rate for other packets. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
l2-others-max |
Maximum L2 packet rate for L2 packets that are not ARP packets. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
pri-type-max |
Maximum overflow rate of priority type traffic. Includes L2: HA, 802.3ad LACP, heartbeats. L3: OSPF. L4_TCP: BGP. L4_UDP: IKE, SLBC, BFD. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
sctp-max |
Maximum SCTP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
200000 |
||||||
tcp-others-max |
Maximum TCP packet rate for TCP packets that match none of the 3 types above. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
600000 |
||||||
tcpfin-rst-max |
Maximum TCP carries FIN or RST flags packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
600000 |
||||||
tcpsyn-ack-max |
Maximum TCP carries SYN and ACK flags packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
600000 |
||||||
tcpsyn-max |
Maximum TCP SYN only packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
600000 |
||||||
udp-max |
Maximum UDP packet rate. |
integer |
Minimum value: 1000 Maximum value: 1000000000 |
600000 |