Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lucas_Correia
New Contributor

Session expires lower than session duration

Hi, 

 

My question is, is there a way to disconnect a session after a specific period of time, whether they are idle or not. For example, we have sessions from the fortigates to my Fortianalyzer, using the port TCP/514, that never expires.

I already tried set config system session-ttl on this port but it never expires. 

 

Running v5.4.8,build1183 (GA) on FGT 60D;

 

--Lucas

2 REPLIES 2
EMES
Contributor

Create a new service in the CLI you can set the session timeout per service and some other options.

try the commands below : 

 

config firewall service custom

edit testservice

set ?

EMES

Although you did mention where they are idle or not which is not possible. I will say you can probably do something with the timeouts , make them really short on that one service as opposed to doing it for the entire firewall.

 

Labels
Top Kudoed Authors