Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mattw
New Contributor III

How to enable the "Always Up" feature silently from FortiClient EMS

Hello,

We are using FortiClient for SSL VPN, centrally managed via an EMS server.

I can't find a way of silently enabling the Always Up feature from EMS (so that if a user loses the network, FortiClient is automatically reconnect when the network is back up).

It seems that the only way to make this work is to edit the SSL VPN tunnel in EMS and check the "Show Always Up Option".
- Note: All this does is show an option for the end user to enable/disable the feature.

The end user then has to check the Always Up setting on their individual ForitClient instance.

I would have thought there would be a way of enabling this centrally in EMS.

Any ideas? Maybe I'm being blind and missing something obvious.

Thanks in advance!

9 REPLIES 9
srajeswaran
Staff
Staff

on EMS, under XML config can you check if you see the below setting ?

Always_up.png

Can you try changing the <show_alwaysup>0</show_alwaysup> to <show_alwaysup>1</show_alwaysup>  and test?

 

 

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

mattw
New Contributor III

Hi @srajeswaran ,

Thank you for the suggestion. All this setting does is make the option visible for the user to enable/disable. It doesn't actually enable the feature, just the ability for the end user to check/uncheck the option from the FortiClient GUI.

srajeswaran

yeah, my mistake. I just realized it, it is enabling the option. Let me check further.

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

mattw
New Contributor III

Hey no worries, thank you for your input!

5Lights
New Contributor

Dont suppose you found a fix for this?

mattw
New Contributor III

Hi @5Lights,

I did! Sorry, I should have updated this thread, tut tut tut.

Anyway, in EMS, under the XML config, look for a tag called <keep_running> and change the value from 0 to 1. That should do it.

Let us know if it works for you.

Cheers!

JuanZion
New Contributor

Am managing the SSL VPN tunnels via EMS, I couldn't find an option to silently enable the "Always Up" feature on FortiClient instances. Despite checking the "Show Always Up Option" in the EMS server, it seems that this only exposed the option for me gb what is as an end user to manually enable or disable the feature on my individual FortiClient application.

mattw
New Contributor III

@JuanZion,

Did you do what I suggested above: In EMS, under the XML config for the SSL VPN tunnel, look for a tag called <keep_running> and change the value from 0 to 1.

Bean28
New Contributor

Hello,

I have been struggling with trying to enable this ability after Forticlient 7.0.7 . With 7.0.7 (and prior) we were able to use the <keep_running> option without Always Up and client VPN connections would automatically re-connect if the connection was briefly lost. With any version after 7.0.7 (ex. 7.0.10, 7.2.2, etc) the VPN connection does not automatically reconnect with only <keep_running> and the only way we've been able to get it to work is to have Always Up enabled and checked. I've even heard from Fortinet support that Always Up is now required.

Has anyone figured out a way to get this to work without Always Up? The user support calls  are frustrating to receive when this functionality should be admin controlled (and not user controlled).

Labels
Top Kudoed Authors