Skip to main content
Khidzir_MN
Staff
Staff
October 7, 2024

Technical Tip: How to insert the Client IP in the TCP Option for Layer 4 TCP Virtual Server

  • October 7, 2024
  • 0 replies
  • 622 views

Description

This article describes how to insert the Client IP information in the TCP Option for Layer 4 TCP Virtual Server.
It is maybe necessary to preconfigure other respective Virtual Server setup and Application Profiles setup and refer to the documentation at the end of this article for more information on the respective configurations.

Scope

FortiADC and FortiADC-VM v7.4.4 or later.

Solution

FortiADC v7.4.4 or later supports Client IP Insertion in TCP Option, which inserts the Client IP information in the TCP Option where there is a requirement to identify the Client IP for Layer 4 TCP Virtual Server.

 

Example:

The TCP option with Client IP information from the packet capture. TCP Option number 35 is used in the example.

 

tcp_option_with_client_ip_information.png

 

CLI commands:

config load-balance profile
edit "LB_PROF_TCP_example"
set type tcp
set client-ip-tcp-option enable
set client-ip-tcp-option-number 35
set timeout_tcp_session 100
set timeout_tcp_session_after_FIN 100
set timeout_send_rst disable
set ip-reputation disable
unset geoip-list
unset allowlist
next
end


Refer to the site below for the available TCP Option number:
Transmission Control Protocol (TCP) Parameters

 

Related documents:

What's New: Client address insertion in Layer 4 TCP virtual server

Configuring virtual servers

Configuring Application Profiles

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!