Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AdaptusSupport347722
New Contributor

Forticlient Auto Disconnected

Hi,

 

Recently, most of our users are encountering Forticlient auto disconnected many times in a day. Although the internet connection are stable but the issue keep happening. Also update to latest version but it does not improve. Since we are not using full version, we could not get much help from Fortigate Vendor. Anyone encounter this issue before and how you resolve it? Appreciate if you could suggest any option that can be resolve this issue. Thank you

9 REPLIES 9
gfleming
Staff
Staff

If it's affecting multiple users it's likely an issue with the FortiGate and/or your Internet.

 

How are you confirming that your Internet connection is stable?

Cheers,
Graham
AdaptusSupport347722

Hi Graham,

 

During the issue happen, they are still able to access internet.(eg.. user still can send email,& browsing internet). 

gfleming

So using FortiClient and having disconnects implies users are remote and connecting to VPN. I am making this assumption that the VPN connection is terminating and disconnecting users.

 

If that is correct, you have to understand that if the user can still access the internet after disconnecting from VPN, that just tells you *their* internet is fine.

 

What we need to focus on is the internet link on your FortiGate that is servicing the VPN clients. As soon as clients disconnect they will no longer be relying on the internet that is connected to your FortiGate.

 

So, how are you confirming the FortiGate's internet connection is stable?

Cheers,
Graham
AdaptusSupport347722
New Contributor

Hi Graham,

How I can confirm is I  continuously ping to google,user local PC gateway and our fortigate internet IP from Client PC. But I did not see any packet drop or request time out in ping result when the issue happened.

 

gfleming
Staff
Staff

OK a couple thoughts:

1. A ping from client to your Fortigate doesn't tell you a whole lot.

2. Is your FortiGate potentially overloaded? What model is it?

3. How much bandwidth is it processing? If you don't have one already, add and check bandwidth graph for your WAN interface. Is it close to capacity?

4. How many VPN clients?

5. Do you see any CPU spikes on the dashboard?

6. Do clients get disconnected at the same time? Or is it pretty random?

Cheers,
Graham
AdaptusSupport347722

Hi Graham,

 

2. 300D

3. 24 hrs average usage - max 250mbps, we subscribed 800 mbps.

4. We have over 500 VPN users

5. CPU usage always 10%, found no spike

6. Pretty random

gfleming

The 300D's recommended maximum for SSL VPN users is 500. You might be hitting resource limitations...

Cheers,
Graham
AdaptusSupport347722

Hi Graham,

 

The total concurrent VPN users session only 184 for daily. Sometimes reach to 250 concurrent session. It never reach to 500 users concurrent session.

gfleming

OK well the FW is doing other things as well. 500 max assumes it is doing nothing else but servicing SSL VPN clients.

 

That said, i guess next place to look is FGT logs. Check logs for SSL VPN messages. Any reassons for disconnects showing up in there?

Cheers,
Graham
Labels
Top Kudoed Authors