Description | This article describes a known issue related to guest management on FortiGate. Specifically, guest credentials do not expire after selecting the 'Expire' button in the GUI. |
Scope |
FortiOS v7.4.8, v7.6.3, and earlier. Guest Management on FortiGate. |
Solution |
When administrators manually expire a guest user’s account by using the 'Expire' button under User & Authentication -> Guest Management (by right-clicking the user and then selecting 'Expire'), the guest user may remain authenticated and able to access network resources.
Example Configuration: Administrators create temporary user accounts with a defined expiration time to grant access to network resources. Before creating guest user accounts, a guest group must be configured. The guest user ID can be an email address, a randomly generated string, or any identifier assigned by the administrator. Passwords can also be set manually by the administrator or generated automatically. The guest group configuration controls the fields available when creating guest user accounts in Guest Management.
The configuration used in this article is explained in the administration guide. When a user connects, the user's session appears in the authentication list:
diagnose firewall auth list
After expiring the token via the GUI, the user session remains in the authentication list and still has access:
When the token is manually expired using the button, the token is shown as expired in the FortiGate GUI, but the user still appears in the CLI output of 'diagnose firewall auth list' and is able to connect with the expired token.
diagnose firewall auth list
Removing the entry from the auth list will terminate the existing connection, preventing the user from reconnecting with the same guest credentials. Once credentials have expired, the session should be disconnected. See Technical Tip: How to de-authenticate a specific authenticated user for additional filters that can be used to specify which user(s) should be cleared.
diagnose firewall auth filter user <username> diagnose firewall auth clear To resolve this issue, update the FortiGate to version 7.6.4. For more details, refer to Issue 1124183 in the FortiOS Release Notes. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.