Skip to main content
bkarl
Staff
Staff
July 16, 2026

Technical Tip: TACACS session duration

  • July 16, 2026
  • 0 replies
  • 16 views

Description

This article describes the duration of TACACS sessions and how to manage them during testing. The user may need to modify the session duration to apply changes to authorization profiles quickly.

Scope

FortiAuthenticator.

Solution

To manage TACACS sessions, go to Authentication -> User Account Policies -> General.


On the Session Expiry tab, there are the following settings:

b8b00593.png


Modify the session duration as needed. During testing, it is recommended to set a short session duration to validate changes to authorization rules quickly.

Set a short session duration to allow for quick testing of authorization rule changes.

Let the session expire to test new connections.


For more information, refer to the Creating Authorization Rules documentation.


Remember that this setting permits establishing how long the authenticated user will be able to run commands once is considered by FortiAuthenticator as an authorized user.


The default value is set to 28800 seconds, as the picture displays above.


Nowadays, FortiAuthenticator is not able to clear sessions quickly before the time expires. This task should be performed manually by an administrator.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!