Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
morteza
New Contributor

filtering packets based on the ip options

hello all

we have a fortigate 600d fortiOS v5.4.4 and i want to deny any packet that have time-to-live (ttl) value less than 125.

what should i do?

1 REPLY 1
morteza
New Contributor

solved ! 

i created a custom ips sig as following:

F-SBID( --name "IP.TTL.Filter"; --attack_id 4478; --ip_ttl < 125;)

Labels
Top Kudoed Authors