Fortinet white logo
Fortinet white logo

Administration Guide

Active sessions

Active sessions

The Active Sessions tab in Monitoring provides a way to oversee activities of launched secrets from FortiPAM. The page lists out all the launched secrets with information such as source IP: Port, destination IP: Port, the application that is launched and username, etc.

Additionally, a Disconnect button is available when you select a secret session. Using the Disconnect button, you can terminate the selected launched secret session. This monitor is especially powerful in situations where there is malicious activity being conducted by a user because the administrator will be able to terminate the session right away with the Disconnect button to protect the integrity of the secret.

Disconnecting native non-proxy sessions is currently not supported.

On the top, the following widget is displayed:

  • Username: displays the total count of the users using secrets.

For every session, the following columns are displayed by default:

  • Session ID

  • Username

  • Account Name

  • Token ID

  • Source

  • Source Port

  • Source Location

  • Destination: The actual target server IP address.

  • Destination Port

  • Gateway: The gateway IP address.

  • Gateway Port

  • Gateway Name: The gateway name.

  • Application

  • Duration (sec)

The Active Sessions tab contains the following options:

Group by

Select to group the active sessions by either username or secret.

Refresh

To refresh the contents, click the refresh icon.

Search

Enter a search term in the search field, then hit Enter to search the active sessions list. To narrow down your search, see Column filter.

For an active secret session, you can terminate the session by clicking Disconnect the current secret session as you live stream the session.

For information on over-the-shoulder monitoring, see Over-the-shoulder monitoring (Live recording).

Active sessions

Active sessions

The Active Sessions tab in Monitoring provides a way to oversee activities of launched secrets from FortiPAM. The page lists out all the launched secrets with information such as source IP: Port, destination IP: Port, the application that is launched and username, etc.

Additionally, a Disconnect button is available when you select a secret session. Using the Disconnect button, you can terminate the selected launched secret session. This monitor is especially powerful in situations where there is malicious activity being conducted by a user because the administrator will be able to terminate the session right away with the Disconnect button to protect the integrity of the secret.

Disconnecting native non-proxy sessions is currently not supported.

On the top, the following widget is displayed:

  • Username: displays the total count of the users using secrets.

For every session, the following columns are displayed by default:

  • Session ID

  • Username

  • Account Name

  • Token ID

  • Source

  • Source Port

  • Source Location

  • Destination: The actual target server IP address.

  • Destination Port

  • Gateway: The gateway IP address.

  • Gateway Port

  • Gateway Name: The gateway name.

  • Application

  • Duration (sec)

The Active Sessions tab contains the following options:

Group by

Select to group the active sessions by either username or secret.

Refresh

To refresh the contents, click the refresh icon.

Search

Enter a search term in the search field, then hit Enter to search the active sessions list. To narrow down your search, see Column filter.

For an active secret session, you can terminate the session by clicking Disconnect the current secret session as you live stream the session.

For information on over-the-shoulder monitoring, see Over-the-shoulder monitoring (Live recording).