Technical Tip: Information about firewall-session-dirty
Description
Available options:
- Check-all: Re-validate all sessions affected by the firewall policy change. This is the default setting.
- Check-new: Keep existing sessions and check new connections only.
- Check-policy-option: Use the option selected in the firewall-session-dirty field of the firewall policy.

The firewall policy-level setting is available only if the VDOM-level setting is set to check-policy-option.
Note:
Policy Level:
- Check-all: Re-validate all sessions affected by the firewall policy change. This is the default setting.
- Check-new: Keep existing sessions and check new connections only.
edit <id>
set firewall-session-dirty < check-all | check-new >
next
end
Note that there may be a CPU penalty if there are more than 2,000 firewall policies. For more information, refer to the related KB article.
Validation:
state=may_dirty
Event: [changes applied to firewall policy]
state=dirty may_dirty <----- Sessions marked 'dirty' for firewall policy validation or route changes.
[continuous traffic cause firewall policy and route re-validation>
state=may_dirty <----- Validation done. 'dirty' marker removed.
Scenario 2:
With firewall-session-dirty check-new, active sessions would be marked as persistent, and no firewall policy validation or route change lookup for existing active sessions would occur.
state=persistent
This setting can restore even a VDOM configuration file without affecting established sessions.
To change the firewall-session-dirty option from the FortiManager: Go to Device Manager -> Device & Groups -> Select the FortiGate (for FortiGates without VDOM) and the VDOM (for FortiGates with VDOMs configured) to change the firewall-session-dirty option -> Select the 'CLI Configuration' TAB -> Select the '+' on the left of 'System' -> Select 'Settings' –> Scroll down the System settings list on the right until the firewall-session-dirty row makes it possible to compare and choose available options on the menu to the right.
To push the configuration change to the FortiGate, select the Install Device Settings (only) button in the top horizontal bar and follow the Install Wizard.
When using NGFW Policy-based mode, the only option available is check-all.
Related documents:
