Hi,
My question is, is there a way to disconnect a session after a specific period of time, whether they are idle or not. For example, we have sessions from the fortigates to my Fortianalyzer, using the port TCP/514, that never expires.
I already tried set config system session-ttl on this port but it never expires.
Running v5.4.8,build1183 (GA) on FGT 60D;
--Lucas
Create a new service in the CLI you can set the session timeout per service and some other options.
try the commands below :
config firewall service custom
edit testservice
set ?
Although you did mention where they are idle or not which is not possible. I will say you can probably do something with the timeouts , make them really short on that one service as opposed to doing it for the entire firewall.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1110 | |
758 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.