FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Ted
Staff
Staff
Article Id 260431
Description

This article describes a system event indicating NTPD clears active sessions 'User: from ntpd clean active IPv4 sessions'.

Scope FortiGate.
Solution

In general, when an admin user clears active sessions via GUI or CLI, a system event with a warning severity level is logged as below.

 

logid="0100036883" type="event" subtype="system" level="warning" vd="root" logdesc="Clear active sessions" user="admin" ui="console" method="console" msg="User:admin from console clean active IPv4 sessions,( filter:none)"

 

Meanwhile, when an NTPD daemon automatically clears active sessions to optimize NTP synchronization, a similar system event can be logged as below.

 

logid="0100036883" type="event" subtype="system" level="warning" vd="root" logdesc="Clear active sessions" ui="ntpd" method="unknown" msg="User: from ntpd clean active IPv4 sessions,( filter:sintf:<sintf>;dintf:<dintf>;proto:17-17;source port:123-123;dest port:123-123;)"

Contributors