Skip to main content
duenlim
Staff
Staff
November 13, 2024

Technical Tip: How to verify the block ICMP timestamp on FortiGate interface

  • November 13, 2024
  • 0 replies
  • 4925 views

Description

This article describes how to usethe  built-in sniffer packet tool to make sure the block ICMP timestamp is effective on the FortiGate Interface.

Scope

FortiGate.

Solution

By default, FortiGate will respond to the ICMP Timestamp reply if the ICMP Timestamp is received. The images below demonstrate the Nmap ICMP Timestamp sent to FortiGate's Interface and found 1 host up. 

NMAP.JPG

 

The FortiGate built-in sniffer packet results show the ICMP Timestamp request packet comes in, and FortiGate returns the ICMP Timestamp reply.

This information could have potential risks. Refer to this KB article: Technical Tip: Block ICMP timestamp on FortiGate interface while keeping ping enabled.

 

NMAP2.JPG

 

Once the Block ICMP Timestamps. The built-in sniffer packet result shows FortiGate will stop responding to ICMP Timestamp reply.

 

NMAP3.JPG

 

Once Block ICMP Timestamps is enabled, the FortiGate drops incoming ICMP Timestamp requests instead of processing them. Therefore, it does not generate an ICMP Timestamp Reply. This prevents remote devices from obtaining the FortiGate’s system-time information and reduces potential device fingerprinting/information disclosure.

Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!