Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Road_Warrior
New Contributor

tcp-options

Hello, Thanks for taking the time to read my post. My post is on enabling/disabling TCP Timestamps. So there is a customer that has had a pentest. One of the results from the test was a low priority item, but I have been asked to address it. <The Item> - TCP timestamp requests enabled - - Server confidentiality impacted. - A remote attacker could possibly determine the amount of time since the computer was last booted. - Fix TCP timestamps are generally only useful for testing, and support for them should be disabled if not needed. <END of Item> So here is my question... I see that I can disable the Global system config item TCP-options (this includes the Timestamps). So as a test, I do the following... # config system global #<global> set tcp-option disable - Now I' m thinking that this shouold be saved, since cfg-save is auto - but upon further review of the config, I see that it is still enabled. When I do a #execute cfg save it tells me that there is no changes. Am I missing something here? How do I disable TCP-options and will anything break if I do it? These sites are using Firewall policy, OSPF/static routing and VPN. Device = Fortigate 60B running 3.00 B730 MR7 Patch1. Thanks for your time and patience. RW
2 REPLIES 2
Carl_Wallmark
Valued Contributor

Hi, after you typed your command you should type " end" then your config is saved. For example: config system global set tcp-option disable end

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Road_Warrior
New Contributor

Thank you. That did the trick. I know TCP options are a long conversation, but is there a real need for this to be enabled? Thanks again, RW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors