Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fabricio
New Contributor

Ghost Session

Good Morning, On my FortiGate 200B that is configured with HA, one session authenticated by FSSO, since 1 day and 15 hours that this session not die. This session was started by on Wifi Connection. How Can i kill this session by command line ? Already rebooted the Cluster " HA" , cleaning cache User List on tow FSSO. Tk

Fabri­cio Castro Maluf Analista de Infraestrutura

Fabri­cio Castro Maluf Analista de Infraestrutura
3 REPLIES 3
Christopher_McMullan

Can you see the session by running: diag sys session filter .... //--filter for parameters of the session, like port of IP diag sys session list Try to kill it: diag sys session clear //--ONLY do this with a filtered list Then check again: diag sys session list If the session is gone, remember to clear your filters: diag sys session filter clear

Regards, Chris McMullan Fortinet Ottawa

Fabricio

No list result on prompt when i set filter ip addres 10.10.0.10. Look at the print, is the session that did not die

Fabri­cio Castro Maluf Analista de Infraestrutura

Fabri­cio Castro Maluf Analista de Infraestrutura
Christopher_McMullan

What you' re describing isn' t a session, per se, as much as an FSSO authentication event, which is why it survived a reboot. What is the status of user ' FM06440' on your collector agent (if you are using one)? Have you chosen to view all FSSO logons under the User Monitor as well as actual users of firewall policies? The clue here is that there is no Policy ID mentioned, therefore, no session. If there was traffic, there would be a matched policy.

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors