Description |
This article describes some situations where it is necessary to configure auth-timeout with auth-timeout-type hard-timeout. But after auth-timeout value reaches to the setting value. “Time Left” at GUI of the user has been reduced until 0 second. Then “Time Left” value becomes 47721 day(s). The user can not access to Internet and it doesn’t have “log-in” page to pop up for the user to log in again. |
Scope | FortiGate v7.2.x |
Solution |
For example:
config user setting set auth-cert "Fortinet_Factory" set auth-timeout 960 set auth-timeout-type hard-timeout end
config firewall policy edit <firewall policy ID> set srcintf "port6" set dstintf "port1" set action accept set srcaddr "Wireless" set dstaddr "all" set schedule "always" set service "ALL" set nat enable set groups "UserRadius" next end
config user group edit "UserRadius" set auth-concurrent-override enable set auth-concurrent-value 3 set member "Radius5" next
config user radius edit "Radius5" set server "192.168.15.95" set secret ENC nXCrGfGIBgskHBZHTbxDGFKA9P2zhi3uAzdFRTnkRLzMAV6rp/f2820eEDfCO0r+NSuWbXHP70pSqe/iGMmN+9aTbOHsPSXUylX1Y/b+bYsTJZXmne63gzybEs7L02A/jF3OIRxKVv2cF14lmd54u3ALO/Di/cR3Aqn2klFwLOO4FovEM+sNwap5v+O5ybxw/bAppg== set password-renewal disable next end
The device of that username can not access to internet. When the user tries to access to Internet, it doesn’t have 'log-in' page to pop up for the user to log in again.
To fix:
Go to Dashboard -> Users & Devices -> Firewall Users -> Choose the user focusing on (the one with 'Time Left' : 47721 day(s)) -> Select the Deauthenticate' button.
When the user tries to access to Internet ,then 'log-in' page will show up for the user to be able to fill up username and password to access to Internet again.
It is necessary to upgrade FortiGate firmware version to be v7.4.4 and above. Do so under Dashboard -> Users & Devices -> Firewall Users -> Time Left. After auth-timeout reaches the setting value, the 'Time Left' of the user will be reduced until 0 second and that username will disappear. Session is removed from authentication list. When the user tries to access to Internet, the 'log-in' page will show up for the user to be able to fill up username and password to be able to access to Internet again.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.