NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator runs 'diagnose sys session list' and sees sessions with 'proto=6 proto_state=02' and a long duration. The administrator is troubleshooting why sessions are not being terminated after a policy change that should block the traffic. What does 'proto_state=02' indicate?
⚠ Common exam trap
Many candidates confuse the numeric 'proto_state' values with generic TCP states from RFC 793, but Fortinet uses its own mapping where '02' specifically means ESTABLISHED, not TIME_WAIT or FIN_WAIT, leading to incorrect assumptions about session termination behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is in established state (TCP connection active)
In Fortinet's 'diagnose sys session list' output, 'proto=6' indicates TCP, and 'proto_state=02' maps to the TCP established state (ESTABLISHED). This means the session has completed the three-way handshake and is actively passing data. A long duration in this state explains why the session persists even after a policy change that should block new traffic—the existing session remains in the kernel session table until it times out or is explicitly cleared, because FortiGate's stateful inspection does not retroactively terminate established sessions upon policy modification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session is in TIME_WAIT state
Why it's wrong here
proto_state=02 marks the TCP handshake stage, not TIME_WAIT, which follows connection teardown. TIME_WAIT is tempting because long-lived sessions are assumed to be lingering after closure, but this session never reached established state, so no teardown timer applies.
- ✗
The session is in SYN_SENT state, waiting for a SYN-ACK
Why it's wrong here
proto_state=02 denotes the session is established, not SYN_SENT, so the session is legitimately open and will persist until idle timeout or a reset. SYN_SENT is tempting because it also describes a TCP handshake phase, and would apply when the firewall has sent a SYN but received no SYN-ACK.
- ✓
The session is in established state (TCP connection active)
Why this is correct
proto_state=02 denotes an established TCP session, meaning the three-way handshake completed and the connection remains active. FortiGate keeps such sessions alive until FIN or RST, so a policy change alone will not terminate them; they must be cleared manually.
- ✗
The session is in FIN_WAIT state, closing the connection
Why it's wrong here
proto_state=02 denotes the TCP handshake stage, meaning the session is still establishing, not closing; FIN_WAIT corresponds to a later teardown state. It is tempting because a long-duration session appears to be ending, but a half-open session persists precisely because the handshake never completed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.