Courseiva

Interpreting FortiGate Session List Output

You run the following command on a FortiGate:

``` diagnose sys session filter dport 443 diagnose sys session list ```

The output shows: ``` proto=6 proto_state=01 duration=3600 expire=3599 ```

What does this indicate?

⚠ Common exam trap

A common mix-up: candidates confuse `duration` (time since session creation) with idle time, and misinterpreting `proto_state=01` as a handshake state (SYN_SENT) instead of the correct ESTABLISHED state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session has been established for 3600 seconds and has 3599 seconds remaining before timeout.

The output shows `duration=3600` and `expire=3599`, which indicate the session has been active for 3600 seconds and has 3599 seconds remaining before timeout. The `proto=6` confirms TCP (protocol 6), and `proto_state=01` represents the TCP state for an established connection (ESTABLISHED), not a handshake state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The session has been established for 3600 seconds and has 3599 seconds remaining before timeout.

    Why this is correct

    In FortiGate's session table output, the Duration field shows the total time elapsed since the session was first created, while the Expire field shows the remaining time before the session is removed from the table. A duration of 3600 seconds means the session has been active for exactly one hour, and an expire value of 3599 seconds indicates that timeout will occur in just under one hour. This interpretation is correct because these fields measure session age and remaining lifetime, not idle time or connection state.

  • ✗

    The session is using TCP state 01 (SYN_SENT) and is still in the process of establishing.

    Why it's wrong here

    The Proto_state value of 01 in a FortiGate session table does not represent SYN_SENT; rather, it is a bitmask that typically indicates a fully established TCP connection. If a session were in SYN_SENT, it would be in the middle of the three-way handshake and would not have a duration of 3600 seconds, as handshakes complete in milliseconds. Furthermore, a session in SYN_SENT would not yet have an established entry with a stable duration and expire timer, so interpreting this as an establishing session is factually incorrect.

  • ✗

    The session has been idle for 3600 seconds and will expire in 3599 seconds.

    Why it's wrong here

    The Duration field measures the total time since the session was initiated, not the amount of time the session has been idle. Even if the session has been constantly transmitting data, the duration would still read 3600 seconds, so it does not imply idle time. The Expire value is the countdown to the session's timeout, which is typically reset by traffic; confusing uptime with idle time is a common misunderstanding that leads to incorrect conclusion about the session's activity level.

  • ✗

    The session is using UDP protocol and will expire in 3599 seconds.

    Why it's wrong here

    In the output of 'diagnose sys session list', the Proto field is an IP protocol number, and a value of 6 corresponds to TCP, not UDP (which would be 17). Therefore, a session with Proto=6 cannot be a UDP session, regardless of the expire value shown. The expire value simply indicates how many seconds remain until the session times out, and it does not influence the protocol type. Recognizing the protocol number mapping is essential for accurate session table interpretation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You run the following diagnose command on a FortiGate and see the output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 ... What does the 'proto_state=01' indicate?

hard
  • A.The session is UDP, indicated by proto_state 01
  • ✓ B.The session is in a half-open state (SYN_SENT)
  • C.The session has been fully established
  • D.The session is being terminated

Why B: In FortiGate session diagnostics, 'proto_state=01' for a TCP session (proto=6) indicates the session is in a half-open state, specifically SYN_SENT, meaning the initial SYN packet has been sent but the three-way handshake has not yet completed. This is a transient state before the session becomes fully established (proto_state=02).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.