Created on
09-21-2020
12:36 AM
Edited on
09-11-2025
01:56 AM
By
Jean-Philippe_P
Description
This article describes how to select the level of checking performed on packet headers.
Scope
FortiGate.
Solution
If a packet fails header checking, it is dropped by the FortiGate. The header properties checked can be configured using CLI with the following command:
config system global
set check-protocol-header {loose | strict}
end
Note:
Enabling strict header checking disables all hardware acceleration on the device, including NTurbo and IPsec encryption/decryption offloading. This can have a performance impact. See the FortiSwitch v7.6.4 Hardware Acceleration Guide: Strict protocol header checking disables hardware. acceleration.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.