Hi,
I need to understand the risks of enabling tcp-session-without-syn for asymmetric environment. Can someone help to explain to me all the risks if I enable this?
Thank you
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @arie_arie ,
Normally, a TCP session starts with a three-way handshake, beginning with a SYN (synchronize) packet. This ensures both sides are aware of the connection and establishes initial sequence numbers for data transmission.Enabling "tcp-session-without-syn" is risky because it bypasses the normal SYN packet handshake in TCP connections. This makes it easier for attackers to hijack sessions, perform replay attacks, confuse connection states, and bypass security measures, thereby compromising network security.
Hi Arie
In addition to Atlas' explanation, please check this two tech tips.
Also let me add, if you need to enable asymmetric routing this should mean that your design still needs improvement because you don't have full control on security.
At lease try use FGSP and/or auxiliary sessions that give more security control comparing with asymmetric sessions.
Hello @arie_arie ,
Normally, a TCP session starts with a three-way handshake, beginning with a SYN (synchronize) packet. This ensures both sides are aware of the connection and establishes initial sequence numbers for data transmission.Enabling "tcp-session-without-syn" is risky because it bypasses the normal SYN packet handshake in TCP connections. This makes it easier for attackers to hijack sessions, perform replay attacks, confuse connection states, and bypass security measures, thereby compromising network security.
Hi Arie
In addition to Atlas' explanation, please check this two tech tips.
Also let me add, if you need to enable asymmetric routing this should mean that your design still needs improvement because you don't have full control on security.
At lease try use FGSP and/or auxiliary sessions that give more security control comparing with asymmetric sessions.
Hi,
How about the UTM inspection in FortiGate? does the UTM inspection still work when enabling tcp-session-without-syn?
Thank you
I don't think so. Without SYN there should be no UTM inspection for that sessions.
Hi,
Thank you for the insight about the feature risk.
If I have 1 FortiGate with 2 uplinks to ISP, where the traffic outgoing to ISP-1 and return traffic going to ISP-2, do I need to enable tcp-session-without-syn to prevent traffic drop of different interface in FortiGate?
Thank you
You may enable auxiliary sessions, this will keep UTM in this case.
There any many tech tips about auxiliary sessions but you can start here.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SD-WAN-Auxiliary-Sessions/ta-p/229467
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1666 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.