- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Socket connection timeout for specific clients
We have Fortinet firewall 200F
Can we increase socket connection timeout for specific clients OR for specific firewall rule ?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please refer if this could be helpful for you:-
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Session-timeout-settings/ta-p/191228
Salon Raj Joshi
Created on ‎12-03-2024 03:37 AM Edited on ‎12-03-2024 03:42 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I want to increase socket idle timeout value only for TCP ports 1556, 13724, 13782
(no need for UDP ports, no firewall default socket value override adjustment required)
Created on ‎12-03-2024 04:43 AM Edited on ‎12-03-2024 04:43 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The document is still valid for your case.
Focus on the point #3. Create new service objects for your ports. In these service objects, define the port (TCP/xxx) and define the timeout as well (set session-ttl xxx).
Afterwards add these new services to the relevant firewall policies and the modified TTLS will apply only to matching traffic.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks all. Seems we can also create the service from GUI. But I am not able to see the timeout value option when create the service from Services
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is a CLI-only option.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am done. Below are the settings
