Skip to main content
ConstantPing
New Member
November 3, 2016
Question

SSL VPN Timeout

  • November 3, 2016
  • 2 replies
  • 27098 views

We have multiple Authentication Rules in SSL VPN Settings.  We want to apply an auth-timeout for a specific group.  Is that possible?   I see the range is 0-259200 seconds(72 hours), 0 for no timeout under the SSL VPN Settings Root.  But I cannot change the Authentication Rule, maybe I am looking in the wrong area.  

 

Goal is to have one group to only be set for 10 hours before the session dies, and the user has to re-auth.

 

Help, and I appreciate your time. 

 

300D running 5.4.1

 

T

2 replies

Christian1
New Member
April 24, 2018

Hello,

I think there is a way to do this.

Under config user group you can edit "your User Group" and you will find the command authtimeout. This is a timeout per user group in Minutes. Max value 0-43200 Minutes. By default the value is set to 0 no authtimeout.

Best Regards

Christian

emnoc
New Member
April 24, 2018

Goal is to have one group to only be set for 10 hours before the session dies, and the user has to re-auth.

 

i don't think the authtimeout in group setting is going help here. You should try a low value and determine if that will work.

 

if you want the  "sslvpn" to force a authtime  you need to set this in the sslvpn setting

 

config vpn ssl setting

    set auth-timeout <xxxxxxx>

end

 

 

Check in the cli-cmd for the FortIOS in question and double check.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.