From b7bd896edd4121f841ca689e15d902b33d4d95e7 Mon Sep 17 00:00:00 2001 From: Yuri Slobodyanyuk Date: Tue, 8 Mar 2022 18:21:26 +0200 Subject: [PATCH] ongoing additions, changes, and fixes --- cheat-sheets/Fortigate-debug-diagnose-complete-cheat-sheet.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cheat-sheets/Fortigate-debug-diagnose-complete-cheat-sheet.adoc b/cheat-sheets/Fortigate-debug-diagnose-complete-cheat-sheet.adoc index 69f4589..735befb 100644 --- a/cheat-sheets/Fortigate-debug-diagnose-complete-cheat-sheet.adoc +++ b/cheat-sheets/Fortigate-debug-diagnose-complete-cheat-sheet.adoc @@ -603,7 +603,7 @@ just clear Fortigate DHCP database and will start over allocating again. You can |*config sys settings* -*get | grep alg* +*get \| grep alg* |Show what is the current SIP inspection mode. If the output is `default-voip-alg-mode: proxy-based` then the full Layer 7 proxy SIP inspection is on (_ALG_ inspection). If the output is `default-voip-alg-mode: kernel-helper-based` then the Layer 4 _helper_ inspection is on. In both modes Fortigate does IP address translation inside SIP packets (if needed), and opens dynamically high ports for incoming media/voice streams ports. In _ALG_ mode, the Fortigate additionally does RFC compliance verification and more. So, the _ALG_ mode is more prone to cause issues but also provides more security.