FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
kyoneda1
Staff
Staff
Article Id 392688
Description This article describes how the 'Offline timeout' and 'Tag timeout' in FortiClient EMS works.
Scope FortiClient EMS.
Solution

FortiClient EMS version 7.0.1 introduced the ‘Offline timeout’ field, which allows configuration of the duration before an endpoint is considered offline.


In version 7.2.3, the ‘Tag timeout’ field was added, enabling configuration of the time interval between an endpoint being marked offline and the removal of its associated tag.

 

If these timeout values are set too short, tags may be frequently removed and re-added. This can occur when a user steps away from the client PC for a few minutes, causing it to enter sleep mode, or when there is a brief network disconnection. Such frequent changes in tag status can place a load on FortiClient, FortiClient EMS, and FortiGate, as these devices synchronize tag information.

Configuration of these settings is possible depending on the environment.

 

This option can be configured under System Settings -> EMS Settings -> Endpoints Settings by adding ‘Offline timeout’ or ‘Tag timeout’, as described in Configuring EMS settings:

 

timeout_1.png

 

The tag status corresponding to the endpoint status is shown below.

The status is checked on the upper device shown in the image.

 

  1. When the PC is online:

The endpoint is recognized as online, and the tag is active.

 

timeout_2.png
timeout_3.png

 

  1. Immediately after the PC enters sleep mode:

At this point, FortiClient EMS does not yet recognize the endpoint as offline. The tag remains unchanged.


timeout_2.png

timeout_3.png

  1. After the duration configured in the ‘Offline timeout’ setting has passed:
The endpoint is now considered ‘Away’ and ‘Offline’. However, the tag is still retained.
 timeout_5.png
timeout_4.png

  1. After the duration configured in the ‘Tag timeout’ setting has passed:
The tag is removed from the endpoint.

timeout_5.png

timeout_6.png

 

Note:
It is risky to configure these values based solely on theoretical assumptions. Always verify the impact through prior testing to ensure there are no operational issues before applying the settings.

 

Related document:

Configuring EMS settings | FortiClient 7.2.10