Description | This article describes an issue where it is not possible to configure the anti-replay check to be applied per policy for a FortiGate operating in policy-based mode. |
Scope | NGFW Policy-based mode. |
Solution |
When FortiGate is operating in the profile-based mode, it is possible to configure the anti-replay check in global settings as well as the per policy:
config system global Or:
config firewall policy enable Enable anti-replay check. disable Disable anti-replay check.
However, for a FortiGate operating in policy-based mode, anti-replay checking is a global configuration only and cannot be applied per-policy, as this setting is unavailable within security-policies. As a workaround, anti-replay(strict) checks can be applied on a per-policy level by configuring the DoS policies to match traffic for specific security policies, to detect and mitigate SYN-flood and port scan protections.
Related articles:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.