Created on
10-19-2022
04:09 AM
Edited on
02-25-2025
10:25 PM
By
Anthony_E
Description | This article explains how to configure the client-to-site IPsec tunnel (C2S) to automatically close after a specified duration. |
Scope | FortiGate. |
Solution |
In the CLI, open the configuration for the client to the IPsec tunnel. Configure the following:
For example:
FGT # config vpn ipsec phase1-interface
In this example, the VPN will automatically go down 20 minutes after the last connection is made.
Note: The default value of 'idle-timeoutinterval' is 15 minutes. Values can range from 5 to 43200 minutes (30 days).
The following debug output from FortiGate shows details about the VPN after the VPN connection:
FGT # di vpn ike routes list vd: root/0
After 20 minutes, the tunnel (phase1) goes down:
FGT # di de disable
Note: In v7.4.0, the 'diagnose vpn ike log-filter dst-addr4' command has been changed to 'diagnose vpn ike log-filter rem-addr4' and Starting from FortiOS 7.4.1, the 'diagnose vpn ike log-filter rem-addr4' command has been changed to 'diagnose vpn ike log filter rem-addr4'.
To stop the debug, run the following commands:
diagnose debug disable diagnose debug reset
FGT # 2022-10-19 12:08:13.089412 ike 0: in 86D71F91A7693FD74D589BA9844E7CB708100501BE26CC090000006C1EF3A2A2D3584E9719A6105E566029BAA0F23855B15D07054CC07FBEF2A67F9A5F29C80EA59E2AB8EBA4DA1497554AACE3294724194F482DABD5A0DC7B69E83532931CF58D7D55C47EB94B2F31AEA6E9
Since the FortiGate is always acting as a responder in a C2S IPsec tunnel, the client can connect to the VPN again. The tunnel will be down until the client connects to the VPN again.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.