Skip to main content
js2
Staff
Staff
May 5, 2020

Technical Tip: Random stale sessions exhausting IP pool in SSL VPN

  • May 5, 2020
  • 0 replies
  • 10717 views

Description


This article provides steps to clear the random generated stale sessions in SSL VPN which can be viewed in SSL VPN monitor.

 

Scope

 

FortiGate.

Solution
Enable 'Limit Users to One SSL-VPN Connection at a Time' in the SSL VPN portal.

If a user tries to log in twice with the same username while a session is already opened, the FortiGate will ask if the user wants to close the other connection.

Workaround to clear the random generated stale sessions.

 

execute vpn sslvpn list                          <----- To list all SSL VPN sessions and their index numbers.
execute vpn sslvpn del-tunnel <index>            <----- To disconnect a tunnel mode user.
execute vpn sslvpn del-web <index>               <----- To disconnect a web mode user.

 

Related documents:
Resolved issues
Resolved issues

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!