Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
deluuq
New Contributor

TTL hop count change in firewall policy

Hello,

I am currently encountering an issue with an application, which I suspect is caused by the hop count being set too low in the TTL header. There is a FortiGate firewall in the routing path, so I am wondering whether it is possible to modify the hop count field in packets as they pass through the firewall. I noticed there is an option to change the TTL of the session in seconds; however, I have not found any articles on how to change the IP TTL header.

 

Does anyone know if this is possible?

Thanks.

5 REPLIES 5
abarushka
Staff
Staff

Hello,

 

I am not aware that it is feasible to modify TTL hop count. Moreover, TTL hop count modification can potentially cause infinite loop in certain situations.

FortiGate
dovunru2
Visitor

Oh my! I have intermittent issue but only on CentOS clients. I was looking for solution for some time now. And I had my assumptions that it must be something with the network. Now I have new clip in my gun and definitely will look into the TTL issue.

deluuq

Yes, I recently discovered that some applications, for reasons of their own, are designed to set specific TTL values autonomously - maybe it's your case too.

tachen
New Contributor II

deluuq
New Contributor

Thanks will look into it.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors