Skip to main content
Asyraf
Explorer II
April 16, 2024
Question

SSH Session Time Out

  • April 16, 2024
  • 5 replies
  • 6345 views

Hi,

 

We having an issues where the SSH keep timeout when idle. This happen only for 1 IP Segment / VLAN.

 

Not sure if this related to the FW since we have multiple switch in between.

 

User -> Floor Switch -> CS Switch -> FW -> Servers

 

When login and idle for 5s, the session close. In the Fortigate i try config session-ttl based on the FG forum, but still same :

onfig system session-ttl          config port              edit 22                  set protocol 6                  set timeout never                  set start-port 22                  set end-port 22              next          end  end

 Anyone experience on this ?

TQ

5 replies

AEK
SuperUser
SuperUser
April 16, 2024

Hi @Asyraf 

This 5s timeout is probably configured ad ssh client level or ssh server level.

The session default ttl in FG is 1h if I'm not wrong.

AEK
AlexC-FTNT
Staff
Staff
April 16, 2024

You can run a packet capture to prove it. Filter for ssh port and the test IP - 5s is not a lot to wait. You will see who sends the FIN packet. Also, you can check immediately after if the session is still kept in FG (it should be kept for a max 2s after FIN - so you should be fast)

Asyraf
AsyrafAuthor
Explorer II
May 3, 2024

Hi thanks for the suggestion, based on the packet capture (wireshark), i cant find which device (server / client) sending the FIN packet. For this scenario i run the packet capture on client laptop. After 5 - 10s the session close. We have other server that configured using other network segments, the other segment working fine. Only this segment facing the session time out issues. Also @AEK i did configure new linux server (VM) with default setting also same.

AEK
SuperUser
SuperUser
May 3, 2024

Hi Asyraf

Can you try packet capture from FortiGate and try see who (client or server) sends FIN or RST.

Also can you tell more about this segment? Does it have dual path with LB? does it have the same behavior with other encrypted and unencrypted protocols or only SSH? Are you using deep inspection? ... etc

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!