NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator runs the following command and sees output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate about the session?
⚠ Common exam trap
Candidates often confuse `duration` with `expire`, assuming a high duration means the session is about to end, when in fact `expire` shows the remaining lifetime, and `proto_state=01` is the key indicator of an active established TCP session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is an active TCP connection that has been established for 1 hour
The output shows `proto=6`, which is the protocol number for TCP, and `proto_state=01`, which in FortiGate's session table indicates an established TCP connection (state ESTABLISHED). The `duration=3600` seconds means the session has been active for exactly 1 hour, and `expire=3599` seconds shows the remaining time before the session times out. This confirms the session is an active TCP connection that has been established for 1 hour, making option C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session has expired
Why it's wrong here
The session has not expired. The 'expire=3599' field shows the remaining session lifetime in seconds, meaning roughly 3599 seconds are still left before the session is torn down. A session that has expired would be absent from the table or show expire=0, and the 'duration=3600' field confirms 3600 seconds have already elapsed, so the session is currently alive and actively tracked.
- ✗
The session is being blocked by a firewall policy
Why it's wrong here
A firewall policy that blocks traffic would prevent a session from being created in the first place; FortiOS does not log a 'blocked' session as an active entry in the session table. The session listed here is in an established state with both directions of traffic seen, indicating the policy has allowed it. If it were being blocked, you would see a deny log or no session entry at all, not a healthy session with a countdown timer.
- ✓
The session is an active TCP connection that has been established for 1 hour
Why this is correct
This is correct because 'duration=3600' means the connection has been established for exactly 3600 seconds, which is 1 hour, and 'proto=6' is the IP protocol number for TCP. The 'expire=3599' field shows the remaining lifetime in seconds, so the session is still active. An established TCP session with bidirectional traffic is exactly what a FortiGate tracks in its session table, confirming it is not merely a one-way packet but an ongoing connection.
- ✗
The session is using UDP
Why it's wrong here
The session is not using UDP because the protocol field shows 'proto=6', and protocol number 6 is assigned to TCP, not UDP (which is protocol 17). UDP sessions in FortiOS typically appear with a shorter expiry and do not have a TCP 'established' state; they are connectionless and often show 'proto=17' instead. This session's TCP-specific attributes, such as a long duration and stateful tracking, further rule out UDP.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.