Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Remote Desktop Connection session is dropping very often

Greetings all, I have a client that has FG-60 with the latest OS in their head office, and also FG-50 are sitting in their remote sites. The head office and remote sites are connected via private network, however when the remote sites are trying to have RDC into the PCs in the head office over those FGs, they' re experiencing session drop off. It happens like 10 - 20 times during the business hours. When they take the FG-50 out of the network and runs RDC directly from the PC, it runs smoothly without any problems. Do you guys aware if there' s a session time out with FG-50 when it' s in idle stage? I was guessing that caused by the faulty power supply that doesn' t give enough power to the FG that gives intermittent connectivity. Apart from that, I really have no idea why this is happening... Any suggestions guys? Thanks before. Cheers Jascha
13 REPLIES 13
Not applicable

Hi Stefan, I think you' re right about phase2, it should work transparently without killing sessions. There' s not much thing I could help on this one, but this may explain it why your VPN session to the Citrix keeps dropping off: http://kc.forticare.com/default.asp?id=251&Lang=1 If not, maybe anyone could help? Cheers
Not applicable

Hi Jascha I tested a few things out and got the problem reduced to a few things: The tunnel seems to work ok during keyexchange. I tested this by connecting to the Webinterface of the remote Fortigate unit and refreshing the VPN monitor to see what happens when the timeout kicks in. I experienced no delay. Nevertheless a few seconds after the timeout the citrix-client froze. I don' t think its a DHCP issue. It is correct that the remote site has a dynamic ip but the vpn seems to go on, at least to the webinterface. I believe it is a bug in MR10. I will try one other thing later and switch from main mode to aggressive mode to test if the problem is caused by using main mode with a dynamic ip, but since the tunnel seems to work fine (at least for the webinterface) I don' t think that is the meatter. Thanks!
Not applicable

Aggressive mode shows the same behaviour...
Not applicable

I switched of " Enable perfect forward secrecy(PFS)" in the phase2 advanced settings. Still citrix-sessions get killed everytime the phase2 keys are changed. I will go back to my original settings and wait for another release, hoping the problems will be solved...
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors