Skip to main content
boringpeople
New Member
December 4, 2025
Question

How to automatically kill sessions after deleting or disabling a policy?

  • December 4, 2025
  • 1 reply
  • 355 views

I’m deleting (or disabling) a firewall policy, but the sessions that were created under that policy remain active.
firewall-session-dirty is set to clear-all. But it doesn’t clear the existing sessions.

Is there any way to make FortiGate automatically terminate sessions when a policy is disabled or deleted?
Or is manual session clearing (e.g. via diagnose sys session clear) the only option?

1 reply

AEK
SuperUser
SuperUser
December 4, 2025

If am not wrong changing the policy (e.g. service) will make the session dirty. If so then as a workaround you may change it before disabling it.

AEK