We have experienced an issue with specific in-house built applications that worked when not behind our Fortigate 7.x firewall but started to fail when we placed behind it. Turns out the application does not send keep-alive or heartbeats and so the session-ttl kicks on the FortiGate and kills the application. We worked around it by creating a specific rule on the Fortigate to increase the TTL for that application but we are wondering if it is possible to log these events and send to the FortiAnalyzer so we have visibility of this condition going forward as we move more applications behind our firewall?
Solved! Go to Solution.
Hi @shocko ,
FortiGate already writes a traffic-end log every time it ages-out a session. The record has logid 0000000013, type=traffic, subtype=forward, status/end, and the action=timeout (reason=agedout) field that indicates the session died because it hit the session-TTL timer. You can find more details about this event on the below link:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Log-ID-definitions/ta-p/191334
To log and monitor FortiGate session-TTL timeouts in FortiAnalyzer:
After that, every time the FortiGate ages out a session because of the TTL, FortiAnalyzer records it and can alert you, giving clear visibility into applications that lack keep-alives.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hi @shocko ,
FortiGate already writes a traffic-end log every time it ages-out a session. The record has logid 0000000013, type=traffic, subtype=forward, status/end, and the action=timeout (reason=agedout) field that indicates the session died because it hit the session-TTL timer. You can find more details about this event on the below link:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Log-ID-definitions/ta-p/191334
To log and monitor FortiGate session-TTL timeouts in FortiAnalyzer:
After that, every time the FortiGate ages out a session because of the TTL, FortiAnalyzer records it and can alert you, giving clear visibility into applications that lack keep-alives.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Fantastic response. Much appreciated @atakannatak !
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.