Hi All,
From below link, which states we can configure session timeout to Never:
[image]blob:https://forum.fortinet.co...4c6e-9a01-74ad251b6ecf[/image]
but it states it is 'not a secure configuration and should be avoided'.
Understand that having session never expires would hold firewall resources which is undesirable.
Other than this, would there any security features be turned off after configured 'system session-ttl timeout never'?
We just having some legacy applications need to hold the traffic unexpired, but just evaluate what is the trade-off. thx.
Sam
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I can't see how any security features would be disabled with configuring this as never but you need to be very careful with enabling this. Like you've stated it can take all your firewalls memory if sessions are created and not cleared. It would eventually lead to the firewall running out of memory and not working anymore (big security problem).
The maximum value configurable is for 7 days. You can configure this for the services/policies that the legacy servers are using so that it's not a global value. I'd recommend doing this and seeing if the servers work with the 7day timeout first.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.