FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tonylin1
Staff
Staff
Article Id 305280
Description

This article describes why the device shows the status Offline on the section User & Devices of the GUI Dashboard.

Scope FortiGate.
Solution

Offline, it shows 'seen 6167s':

offline.png

 

diagnose user device list | grep b7:22 -A 6
vd root/0 e2:ec:15:57:b7:22 gen 105075 req 0
created 2865980s gen 11641 seen 6167s TWTAC gen 54658
ip 110.110.110.2 src mac
hardware vendor 'Apple' src dhcp id 4670 weight 130
type 'Mobile Generic' src dhcp id 4670 weight 130
os 'iOS' src dhcp id 4670 weight 130
vd root/0 00:34:3f:ec:be:5a gen 80188 req OHUSA/3e

 

Online, it will show 'seen 4s':

online.png

 

diagnose user device list | grep b7:22 -A 6
vd root/0 e2:ec:15:57:b7:22 gen 105412 req 0
created 2866028s gen 11641 seen 4s TWTAC gen 54877
ip 110.110.110.2 src mac
hardware vendor 'Apple' src dhcp id 4670 weight 130
type 'Mobile Generic' src dhcp id 4670 weight 130
os 'iOS' src dhcp id 4670 weight 130
vd root/0 00:34:3f:ec:be:5a gen 80188 req OHUSA/3e

 

Conclusion:

'seen' indicated in the debug command 'diagnose user device list' is the timer that FortiGate saw the packet from the device (MAC).

 

  1. If seen is <= 300s, the status is Online.
  2. If seen is > 300s, the status is Offline.