Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator runs 'diagnose sys session list' and sees sessions with 'proto=6 proto_state=02' and a long duration. The administrator is troubleshooting why sessions are not being terminated after a policy change that should block the traffic. What does 'proto_state=02' indicate?

⚠ Common exam trap

Many candidates confuse the numeric 'proto_state' values with generic TCP states from RFC 793, but Fortinet uses its own mapping where '02' specifically means ESTABLISHED, not TIME_WAIT or FIN_WAIT, leading to incorrect assumptions about session termination behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is in established state (TCP connection active)

In Fortinet's 'diagnose sys session list' output, 'proto=6' indicates TCP, and 'proto_state=02' maps to the TCP established state (ESTABLISHED). This means the session has completed the three-way handshake and is actively passing data. A long duration in this state explains why the session persists even after a policy change that should block new traffic—the existing session remains in the kernel session table until it times out or is explicitly cleared, because FortiGate's stateful inspection does not retroactively terminate established sessions upon policy modification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is in TIME_WAIT state

    Why it's wrong here

    proto_state=02 marks the TCP handshake stage, not TIME_WAIT, which follows connection teardown. TIME_WAIT is tempting because long-lived sessions are assumed to be lingering after closure, but this session never reached established state, so no teardown timer applies.

  • ✗

    The session is in SYN_SENT state, waiting for a SYN-ACK

    Why it's wrong here

    proto_state=02 denotes the session is established, not SYN_SENT, so the session is legitimately open and will persist until idle timeout or a reset. SYN_SENT is tempting because it also describes a TCP handshake phase, and would apply when the firewall has sent a SYN but received no SYN-ACK.

  • ✓

    The session is in established state (TCP connection active)

    Why this is correct

    proto_state=02 denotes an established TCP session, meaning the three-way handshake completed and the connection remains active. FortiGate keeps such sessions alive until FIN or RST, so a policy change alone will not terminate them; they must be cleared manually.

  • ✗

    The session is in FIN_WAIT state, closing the connection

    Why it's wrong here

    proto_state=02 denotes the TCP handshake stage, meaning the session is still establishing, not closing; FIN_WAIT corresponds to a later teardown state. It is tempting because a long-duration session appears to be ending, but a half-open session persists precisely because the handshake never completed.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.