The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

set tcpudpchecksumerror forward

Prev Next

When executed, this command prevents the Sensor from dropping the TCP/UDP/ICMP checksum error packets. The Sensor re-computes TCP, UDP and ICMP header checksums to determine if their corresponding packets have been corrupted. If the checksum fails, the packet is dropped. This is standard Sensor behavior.

The set tcpudpchecksumerror forward command overrides the check, and is useful in situations where the Sensor is located on segments where the IP options Loose Source Record Routing (LSRR) or Strict Source Routing are enabled, which produce valid traffic with invalid checksums that the Sensor would otherwise drop.

This command has no parameters.

Syntax:

set tcpudpchecksumerror forward

Default Value:

This feature is disabled by default. The Sensor is set to drop packets with invalid headers (that is, the value is set to set tcpudpchecksumerror drop).

Applicable to:

NS-series Sensors