Description | This article describes the TCP state machine using output from the 'diagnose sys session stat' command. |
Scope | FortiGate V7.2. |
Solution |
When using 'diagnose sys session stat' to retrieve session statistics on a FortiGate device, various TCP session states can be observed. Below is an example of the output from the 'diagnose sys session stat' command.
Keep in mind that from a FortiGate configuration point of view, there are four TCP timer parameters that can be configured:
TCP Session States Overview: session_count = 446123 — This is the total number of sessions on the FortiGate, including TCP, UDP, and SCTP sessions.
For TCP sessions, there are several possible session states. Below is an explanation of each:
States during the TCP half-open timer:
State during TCP connection established:
States during the TCP half-close timer:
States during the TCP time-wait timer:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.