Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kt001
New Contributor

Lease period of ssl vpn ip address

Is there a command to check or change the lease period of ssl vpn ip address?

 

I got an IP address reception error on an ssl vpn connection. There is still room in the ssl vpn address.

In the past, the lease period when connecting has not expired, so I think it will result in an error.

 

FortiGate80E v6.2.3

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Check "get vpn ssl monitor" and see the second half under "SSL VPN sessions". That would show you the all IP addresses held by sessions.

If FortiClient is "disconnect"ed properly the session on the FGT side should be terminated and the IP is released. But if the FortiClient is closed without a disconnect, it's still up until idle timer ("set idle-timeout" under "config vpn ssl settings") times out. So you can control those dormant sessions from holding IPs by adjusting the timer.

 

FrancisSmith
New Contributor

I would like to know more about this lease period VPN. Would you mind sharing more details? Thank you so much!

Toshi_Esumi

As I said it lasts only the tunnel is up.

Labels
Top Kudoed Authors