Description | This article describes how half-open and half-close timeouts work for GTP tunnels on a FortiCarrier, helping manage tunnel lifecycles. |
Scope | FortiCarrier. |
Solution | How half-open and half-close States are created:
The duration for which these tunnels remain in the table (in either state) is controlled by the half-open-timeout and half-close-timeout parameters, which can be configured in the GTP profile.
Configuring half-open and half-close timeouts:
Below is an example configuration of a GTP profile where the timeouts are set:
config firewall gtp end
Example workflow:
When a GTP Create Session Request hits the above GTP profile, a tunnel is created, and its life is initialized with the half-open-timeout value, 8 seconds. For instance, if the timeout is set to 8 seconds, the tunnel will be deleted if no reply is received within this period.
Below is an example log entry showcasing a tunnel which has its life set to 8 seconds and has 1 request message type 32 under it:
-----------prof=IoT_inbound ref=6 imsi=404277283330042 msisdn=919158002081 mei=86853904.098254.53 ms_addr=:: s11_s4 0-----------
Important notes:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.