Skip to main content
tdhaslett
New Member
March 23, 2020
Question

IPSec VPN 2fa Timeout Settings

  • March 23, 2020
  • 1 reply
  • 6348 views

Hi All,

Is there a way to enforce a timeout on the 2fa authentication period?

We are required to enforce refreshing of 2fa authentication every 24 hours to maintain certification while working remotely. I have not found a way to set this in our Fortigate 200D. I am fine with setting a timeout on the VPN connection itself, thereby forcing a refresh of 2fa.

Also, I would prefer a session timeout rather than an inactivity timeout, if possible.

 

Thanks!

Tim

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    March 23, 2020

    The first thing I found in my Internet search was my own post about idle timeout on this forum two years ago.

    https://forum.fortinet.com/tm.aspx?m=159981

    I don't see other timeout setting in IPsec phase1 config.  Probably auth server side including 2Factor auth doesn't have a mechanism to kill the VPN once it's successfully authorized.

     

    If it were SSL VPN, you could set the session timemout to drop the connection as you wanted.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!