Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mkroslak
New Contributor

SSL VPN timeout

Hello Guys,

 

I am having this kind of issue with SSL VPN.

When my colleague is connected via SSL VPN and his home internet connection fails or drops some packets, Forticlient disconnects and so does SSL VPN. But if he wants to connect again, it fails - Unable to establish the VPN connection. When I check "SSL VPN Monitor" I still see him connected although he is not. When I kill this connection - it works again. But when I dont do that, he needs to wait for about 10 minutes to connect again. It is kind of annoying for this people when they have unstable internet connection, but they have no other choice.

 

Is there any timeout for this ? Any workaround ?

Thank you,

Martin

2 REPLIES 2
ede_pfau
Esteemed Contributor III

Good to see that at least once somebody asks for SHORTENING the idle timeout, not prolonging it for weeks...

 

See https://kb.fortinet.com/kb/documentLink.do?externalID=FD39435 for details.

# config vpn ssl settings
    set idle-timeout 300

So, 5 minutes is the default. You may experiment with lower values but be aware that some applications get sick when the connection is cut off.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
mkroslak

Hello Ede,

 

Are you sure that this is the right timeout?

Because it does not seem that way.

When I am connected via SSL VPN and I plug out my internet cable, Fortigate still see the session UP.

And I cannot reconnect via SSL VPN until this session expires. I have got this timeout set for 24 hours, but this expiration (when my internet goes down) lasts like from 5 to 10 minutes.

After 5-10 minutes the session disapears from SSL VPN Monitor and I can connect again.

Thank you for your time!

Martin

Labels
Top Kudoed Authors