Hi @BPry , I can see the below output for 'show zone-protection'. Is any of these is capable of putting a session to discard from active instead of dropping packet? -------------- IPv(4/6) Filter: discard-ip-spoof: enabled: yes, packet dropped: 0 tcp-reject-non-syn: enabled: yes, (global), packet dropped: 413 tcp-timestamp: enabled: yes, packets modified: 0 discard-tcp-syn-with-data: enabled: yes, packet dropped: 0 discard-tcp-synack-with-data: enabled: yes, packet dropped: 0 strip-tcp-fast-open-and-data: enabled: yes, packet stripped: 21 IPv4 packet filter: discard-icmp-ping-zero-id: enabled: yes, packet dropped: 0 discard-icmp-frag: enabled: yes, packet dropped: 0 discard-icmp-large-packet: enabled: yes, packet dropped: 0 discard-icmp-error: enabled: yes, packet dropped: 87 suppress-icmp-timeexceeded: enabled: yes, packet dropped: 0 suppress-icmp-needfrag: enabled: yes, packet dropped: 0 discard-malformed-option: enabled: yes, packet dropped: 0 discard-overlapping-tcp-segment-mismatch: enabled: yes, packet dropped: 4 strict-ip-check: enabled: yes, packet dropped: 0 discard-tcp-split-handshake: enabled: yes, packet dropped: 0 IPv6 packet filter: routing-header-0: enabled: yes, packet dropped: 0 routing-header-1: enabled: yes, packet dropped: 0 routing-header-4-252: enabled: yes, packet dropped: 0 routing-header-255: enabled: yes, packet dropped: 0 redirect: enabled: yes dest-unreach: enabled: yes pkt-too-big: enabled: yes time-exceeded: enabled: yes param-problem: enabled: yes ---------------------- Thanks in advance.
... View more