Courseiva
Firewall Policies and NAT →mediumMultiple Choice

Session Behavior When Firewall Schedule Expires

An administrator configures a firewall policy with a schedule that allows traffic only during business hours (Monday to Friday, 09:00-18:00). At 17:55 on a Friday, a user establishes an SSH session that is still active at 18:05. What happens to the session when the schedule ends?

Quick Answer

The answer is that the session continues until it ends naturally. This is because FortiGate firewall schedules only govern the creation of new sessions, not the forwarding of already-established ones; once a session is tracked in the session table, the firewall continues to forward its traffic even after the schedule expires, preventing abrupt disruption of active connections. On the Fortinet NSE 4 Network Security Professional exam, this concept tests your understanding of stateful inspection versus policy enforcement—a common trap is assuming the firewall kills all traffic when the schedule ends, but the correct behavior is that only new session attempts are blocked. A useful memory tip: think of the schedule as a bouncer at a door who stops new people from entering after closing time but does not kick out guests already inside the party.

⚠ Common exam trap

A common mix-up: candidates assume schedules enforce a hard cutoff on all traffic, but FortiGate only applies schedules to new session initiation, not to already established sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session continues until it ends naturally

FortiGate firewall policies control the establishment of new sessions based on the schedule. Once a session is established, it is tracked in the session table and continues to be forwarded even if the schedule ends, until the session naturally terminates or times out. This behavior ensures that ongoing traffic is not abruptly disrupted when a schedule expires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is immediately terminated at 18:00

    Why it's wrong here

    FortiGate does not terminate the session instantly at the exact schedule boundary; the session persists until the next policy check or timeout, so immediate termination at 18:00 is inaccurate. It is tempting because the schedule ends at 18:00, but FortiOS re-evaluates sessions asynchronously rather than cutting them at that instant.

  • ✓

    The session continues until it ends naturally

    Why this is correct

    FortiGate schedule expiry only blocks new sessions; established sessions persist because the firewall does not re-evaluate schedule objects against existing session entries. The SSH session therefore survives past 18:00 and continues until the user disconnects or the session times out, satisfying the stem's active-session constraint.

  • ✗

    The session is allowed but new sessions are blocked

    Why it's wrong here

    Session handling is governed by the policy's session timeout and the firewall's TCP state, not by the schedule; an established SSH session persists past 18:00 because schedules gate session initiation only. It is tempting because schedules do stop new connections, which is their actual function.

  • ✗

    The session is terminated after a 60-second grace period

    Why it's wrong here

    FortiGate schedule expiry does not terminate established sessions; existing connections persist until they close naturally or hit an idle timeout, so no grace period applies. The 60-second grace period is tempting because it resembles session-TTL behaviour in other firewalls, and would be correct where a policy explicitly enforces re-authentication or session teardown on schedule change.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator needs to ensure that a firewall policy applies only during business hours (Monday to Friday, 9:00 AM to 6:00 PM). What object should be configured and applied to the policy?

medium
  • A.Service group
  • B.Address group
  • ✓ C.Schedule object
  • D.Traffic shaper

Why C: A schedule object in FortiGate defines time-based conditions (e.g., recurring weekly windows like Monday–Friday 09:00–18:00) that can be applied directly to a firewall policy. When a schedule is attached, the policy is enforced only during the specified time range, making it the correct object for restricting policy activation to business hours.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.