Forum Discussion
no random-sequence-number
Hi,
Can we configure on F5 anything like "no random-sequence-number"? This is used in ACE load balancers.
The purpose for random-sequence-number is explained below.
Randomizing TCP sequence numbers adds a measure of security to TCP connections by making it more difficult for a hacker to guess or predict the next sequence number in a TCP connection. This feature is enabled by default. To enable TCP sequence number randomization after it has been disabled, use the random-sequence-number command in parameter map connection configuration mode.
Is there any option on F5 to implement such thing?
1 Reply
- LPL
Nimbostratus
Hi,
This is disabled by default on BIG-IP when using a Virtual Server with a fastL4 profile. You can enable it by creating a custom fastL4 profile and select: "Generate Initial Sequence Number". This feature refers to RFC1948
Kind regards
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com