Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bkmullen
New Contributor

SSL VPN Disconnects - Keep Alive Setting

Background

Fortigate 500D running FW 5.4.2

FortiClient 5.4.2 & 5.4.3 (recently installed as test)

SSL VPN Client/ Tunnel Mode

 

Multiple clients report inconsistent issues with client disconnects even when client is NOT idle.

Sometimes frequent disconnects (every 60-90minutes), other times the connection stays connected for hours.

 

Is there any Keep Alive setting in Fortigate that can be used to prevent this from disconnecting or keep the tunnel up?

I see "allow Client to Keep Connections Alive" in the SSL VPN Portals/  Full-Access.

Does this Setting result in Caching of the user PW. In other words - if I enable this will the Client PC retain the User PW so that the device can be reconnected without permission and without requesting PW???

 

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

5.4.1 SSL VPN handbook [http://docs.fortinet.com/d/fortigate-ssl-vpn-4] says below in pp42:

"- Allow client to keep connections alive - When enabled, if the user selects this option, the FortiClient should try to reconnect once it detects the VPN connection is down unexpectedly (not manually disconnected by user)."

So it's not going to reduce droppings in your case, but it would just reconnect automatically after a drop.

Rather you want to find out why some of them drop often while others don't. We had similar issues when Antivirus/FW features were unintentionally activated at the FortiClient config file while "VPN only" was chosen for instrallation. And after that was fixed, we found (and proved, more imporantly) the connectivity over the internet from the particular client location was often degraded (dropping some packets). But try enabling local logging first and look at what's in the log at those often dropping clients.

 

bkmullen

Toshi

 

I have some Debug Logs from a Client that disconnects.

What am I looking for in the Log.

We are set to/ supposed to be VPN Only.

I do see 3 references to "Update Task get virus info file failed" in the Log but no other mention of Virus

Toshi_Esumi

Do you see any "VPN errors"?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors