Forum Discussion

yogesh_gaikwad_'s avatar
yogesh_gaikwad_
Icon for Nimbostratus rankNimbostratus
Oct 21, 2015

no random-sequence-number

Hi,

 

Can we configure on F5 anything like "no random-sequence-number"? This is used in ACE load balancers.

 

The purpose for random-sequence-number is explained below.

 

Randomizing TCP sequence numbers adds a measure of security to TCP connections by making it more difficult for a hacker to guess or predict the next sequence number in a TCP connection. This feature is enabled by default. To enable TCP sequence number randomization after it has been disabled, use the random-sequence-number command in parameter map connection configuration mode.

 

Is there any option on F5 to implement such thing?

 

1 Reply

  • LPL's avatar
    LPL
    Icon for Nimbostratus rankNimbostratus

    Hi,

     

    This is disabled by default on BIG-IP when using a Virtual Server with a fastL4 profile. You can enable it by creating a custom fastL4 profile and select: "Generate Initial Sequence Number". This feature refers to RFC1948

     

    Kind regards