Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
us052117
New Contributor

session-ttl : never (fake?)

Hello, I set default session-ttl to Never. Then, #get system session list EXPIRE 18790500sec = (about) 217days Next, #diagnose sys session filter proto 6 #diagnose sys session list ... expire=never timeout=never ... Which is true ? Will the session be cleared after 217days? Is there anyone who knows? [My Unit] FGT80C OS v4.3.15 NAT mode
2 REPLIES 2
drak
New Contributor III

Not sure about the answer but I got curious.

 

Do you really have a connection that will stay idle for more than 217 days ? I'm not sure if any OS would support that.

emnoc
Esteemed Contributor III

Will yes if the  proto is tcp and the sender or receiver  teardowns the sessions but outside of that never means just that "never".

 

But to answer the other poster question, yes you could have a session open that long. I did a lab with a session open for 5 months ( yeap, not quite 217+ days ) but  it could be done & I don't see why it could not be 6 , 9 , 12 or  more months

 

It really depends on the "application" and has nothing to do with the OSes. If you write the application to idle down after so many secs of inactivity, than it will close the session.

 

Now on the firewall, it would probably not be a good thing to use a never ( for all ) unless you have valid reasons.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors