Skip to main content
Contributor III
March 27, 2024

Technical Tip: Dynamically update FortiOS session list table when the external feed list is being updated

  • March 27, 2024
  • 0 replies
  • 1391 views
Description This article describes the capability of FortiOS to check if there is an existing session established with an IP that now belongs to the External Threat Feed list.
Scope FortiGate v7.2.1+.
Solution

Let's assume a network administrator is maintaining the below sample topology:

 Topology.PNG

 

The administrator has configured the FotiGate to receive the malicious list IPs from an internal Threat feed server.

An internal End user has established a communication channel with an External Host and by the time the connection was established the external host's IP did not belong inside the Threat feed database.

However, the threat feed server has updated the database and now the IP of the external host belongs to the malicious IP addresses and the administrator expects all new subsequent packets to be blocked.

 

If a session has been already established, FortiOS needs to mark the session as 'dirty' to be re-examined based on the new criteria.

 

This feature has been implemented in the 7.2.1 GA release with the below VDOM setting command:

 

config system settings
    set ext-resource-session-check enable/disable <----- Default setting.
end

 

With the addition of the above command when there is an updated version of the malicious IP database FortiOS will mark these sessions as 'dirty' and re-evaluate once again.

 

Note:

FortiGate does not re-evaluate existing sessions immediately when an external threat feed is updated. Active sessions are re-evaluated after the smaller value of the configured feed refresh-rate or 30 minutes.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!