Fortigate - reset-sessionless-tcp disabled

Information

Enabling this option may help resolve issues with a problematic server, but it can make the FortiGate unit more vulnerable to denial of service attacks. In most cases you should leave resetsessionless-tcp disabled.

Solution

To set the reset-sessionless-tcp to disabled, use the following command:

config system global
set reset-sessionless-tcp disable
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: FortiGate

Control ID: a773bed646d406ea7e9f127651b8f28669d809c19ef4bb00e0e25f0bb463b36c