Hello,
I'm a bit confused about the command "set profile-protocol-options "default"" when enabling a security profile inside a firewall policy. My understanding is that if we work with the default protocol options, then this command is optional. Is that correct?
However, this command it doesn't appear into the CLI of the firewall policy by default. So, do we have to issue this command or not, when using the default protocol options profile?
Another thing that I don't understand is that this command has to be issued by CLI, it is not available in the GUI. If that is so, what is the purpose of having to issue this command by CLI after you have created the firewall policy?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello aagrafi,
Think of the "protocol-profile-options" setting as the Proxy mode setting. If you are configuring the firewall policy from the GUI, you may notice that as you enable any module that works in proxy-mode, the "Proxy Options" will show up out of nowhere with the default profile. That's "protocol-profile-options" in the CLI.
>>My understanding is that if we work with the default protocol options, then this command is optional. Is that correct?
If your firewall policy contains one or more modules that is in proxy-mode, that policy will be in proxy-mode and the "protocol-profile-options" will be necessary.
If you are running in flow-mode, the "protocol-profile-options" setting is not required and you will not see it in the GUI.
HoMing
Hi Guys:
my VDOM1 was set up as flow base, But I still have to set protocol-profile-options default while I enable flow mode AV profile. why?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.