Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gy14
New Contributor

VPN idle timeout resetting

I have a 200E, idle timeout for ssl vpn is the default of 300 seconds but it doesn't timeout end users at all.  The only KB i can find is

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD48372  

 

I followed the instructions, i have a windows 10 laptop with both [size="2"]SSDP and LLMNR disabled.  Packet capture still grabs what they state as the multicast traffic causing the issue.   "notice the traffic to multicast address 239.255.255.250"[/size]

 

[size="2"]Likewise i run the get vpn ssl and see the timeout decreasing but only for 30 seconds and then its reset to 299.[/size]

 

[size="2"]Am i on the right track that its multicast traffic that resets the timer?  if i've disabled SSDP n LLMNR what is still sending multicast  (no applications on here but forticlient)  anyone have experienced?[/size]

 

[size="2"]thoughts are appreciated.[/size]

 

EDIT: is it because i'm using a my domain DNS IP addresses.   is there a way around this?  don't i need local dns for internal applications & AD auth?

 

 

1 REPLY 1
gy14
New Contributor

This was confirmed with support.  basically idle timeouts don't work due to the constant need for dns / domain traffic.

 

Labels
Top Kudoed Authors