Skip to main content
KensukeShimomura
New Member
September 27, 2024
Question

How to delay tunnel disconnection during shutdown

  • September 27, 2024
  • 3 replies
  • 1268 views

Please give me some advice on what to do when FortiClient shuts down.

 

The system we use runs a script on logoff and records the logoff time on the Server.

However, when using FortiClient, the VPN session is disconnected before the logoff script runs, which prevents the logoff time from being communicated to the server.

 

Is it possible to configure settings to delay tunnel disconnection during shutdown?

3 replies

tpatel
Staff
Staff
September 27, 2024

Hello Sir, 

Can you please enable auto keep alive in tunnel configuration so tunnel will not get disconnect when no data is being processed. 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536#:~:text=FortiGate.&text=Autokey%20Keep%20Alive%3A%20Enable%20the,the%20new%20SA%20without%20interruption.

KensukeShimomura
New Member
September 30, 2024

thank,

 

This does not seem to be the case since we are using the SSL-VPN method.

 

What I would like to know is how to delay the tunnel from being disconnected as soon as the PC's logoff process begins.

 

Is there any better way?

tpatel
Staff
Staff
October 7, 2024

Please set idle timeout to 0 so if user is not active then also connection is going to keep active.

You can also increase auth timeout value so we dont required to reauthenticate again after 8 hours.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!