Question
Disable TCP SYNC check
Hi Does anyone know how to disable the TCP SYNC check on a frotigate 50B? The fortigate acts as default gateway for the majority of traffic. However i need to bounce some traffic to a different gateway on the same internal subnet. This works fine for ICMP traffic but not TCP. This i beleive is due to the fact traffic takes a different return path since on return there is no need to bounce through the fortigate. I had a similar issue when doing this with a netscreen but was able to resolve the issue by disable TCP SYNC check. Since firewals monitor TCP sessions and if packets try and pass out of sequence or with no SYNC flag then they are dropped. thanks