Project

General

Profile

Actions

Bug #10138

closed

FW rules - Manual State timeout settings

Added by matt s almost 5 years ago. Updated almost 5 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
12/31/2019
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

Hi Team,

Any chance you could add a feature to specify/adjust the UDP and TCP state timeouts for a particular host or alias?

i.e a number of SIP phones will need to have a longer state timeout, and it's best not to utilise static port + port forward due to some security vulnerabilities with some older VOIP phones (i.e best with random source port).

So similar to the adjustment of state timeouts as per this thread: https://forum.netgate.com/topic/116472/guide-manually-adjusting-state-timeouts-for-sensitive-services-e-g-voip/2
But for a specific host or alias as specified in a firewall rule?

Thanks guys for your contribution to the project!

Actions #1

Updated by Jim Pingle almost 5 years ago

  • Status changed from New to Duplicate

It's already there for TCP, others are already mentioned in #1635

Actions

Also available in: Atom PDF