Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lucas_Correia
New Contributor

Session expires lower than session duration

Hi, 

 

My question is, is there a way to disconnect a session after a specific period of time, whether they are idle or not. For example, we have sessions from the fortigates to my Fortianalyzer, using the port TCP/514, that never expires.

I already tried set config system session-ttl on this port but it never expires. 

 

Running v5.4.8,build1183 (GA) on FGT 60D;

 

--Lucas

2 REPLIES 2
EMES
Contributor

Create a new service in the CLI you can set the session timeout per service and some other options.

try the commands below : 

 

config firewall service custom

edit testservice

set ?

EMES

Although you did mention where they are idle or not which is not possible. I will say you can probably do something with the timeouts , make them really short on that one service as opposed to doing it for the entire firewall.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors