Fortinet white logo
Fortinet white logo

CLI Reference

config diameter-filter profile

config diameter-filter profile

Configure Diameter filter profiles.

config diameter-filter profile
    Description: Configure Diameter filter profiles.
    edit <name>
        set cmd-flags-reserve-set [allow|block|...]
        set command-code-invalid [allow|block|...]
        set command-code-range {user}
        set comment {var-string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set log-packet [disable|enable]
        set message-length-invalid [allow|block|...]
        set missing-request-action [allow|block|...]
        set monitor-all-messages [disable|enable]
        set protocol-version-invalid [allow|block|...]
        set request-error-flag-set [allow|block|...]
        set track-requests-answers [disable|enable]
        set uuid {uuid}
    next
end

config diameter-filter profile

Parameter

Description

Type

Size

Default

cmd-flags-reserve-set

Action to be taken for messages with cmd flag reserve bits set.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

command-code-invalid

Action to be taken for messages with invalid command code.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

command-code-range

Valid range for command codes (0-16777215).

user

Not Specified

comment

Comment.

var-string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

log-packet

Enable/disable packet log for triggered diameter settings.

option

-

disable

Option

Description

disable

Disable.

enable

Enable.

message-length-invalid

Action to be taken for invalid message length.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

missing-request-action

Action to be taken for answers without corresponding request.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

monitor-all-messages

Enable/disable logging for all User Name and Result Code AVP messages.

option

-

disable

Option

Description

disable

Disable.

enable

Enable.

name

Profile name.

string

Maximum length: 47

protocol-version-invalid

Action to be taken for invalid protocol version.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

request-error-flag-set

Action to be taken for request messages with error flag set.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

track-requests-answers

Enable/disable validation that each answer has a corresponding request.

option

-

enable

Option

Description

disable

Disable.

enable

Enable.

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config diameter-filter profile

config diameter-filter profile

Configure Diameter filter profiles.

config diameter-filter profile
    Description: Configure Diameter filter profiles.
    edit <name>
        set cmd-flags-reserve-set [allow|block|...]
        set command-code-invalid [allow|block|...]
        set command-code-range {user}
        set comment {var-string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set log-packet [disable|enable]
        set message-length-invalid [allow|block|...]
        set missing-request-action [allow|block|...]
        set monitor-all-messages [disable|enable]
        set protocol-version-invalid [allow|block|...]
        set request-error-flag-set [allow|block|...]
        set track-requests-answers [disable|enable]
        set uuid {uuid}
    next
end

config diameter-filter profile

Parameter

Description

Type

Size

Default

cmd-flags-reserve-set

Action to be taken for messages with cmd flag reserve bits set.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

command-code-invalid

Action to be taken for messages with invalid command code.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

command-code-range

Valid range for command codes (0-16777215).

user

Not Specified

comment

Comment.

var-string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

log-packet

Enable/disable packet log for triggered diameter settings.

option

-

disable

Option

Description

disable

Disable.

enable

Enable.

message-length-invalid

Action to be taken for invalid message length.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

missing-request-action

Action to be taken for answers without corresponding request.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

monitor-all-messages

Enable/disable logging for all User Name and Result Code AVP messages.

option

-

disable

Option

Description

disable

Disable.

enable

Enable.

name

Profile name.

string

Maximum length: 47

protocol-version-invalid

Action to be taken for invalid protocol version.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

request-error-flag-set

Action to be taken for request messages with error flag set.

option

-

block

Option

Description

allow

Allow or pass matching traffic.

block

Block or drop matching traffic.

reset

Reset sessions for matching traffic.

monitor

Allow and log matching traffic.

track-requests-answers

Enable/disable validation that each answer has a corresponding request.

option

-

enable

Option

Description

disable

Disable.

enable

Enable.

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.