Background
Fortigate 500D running FW 5.4.2
FortiClient 5.4.2 & 5.4.3 (recently installed as test)
SSL VPN Client/ Tunnel Mode
Multiple clients report inconsistent issues with client disconnects even when client is NOT idle.
Sometimes frequent disconnects (every 60-90minutes), other times the connection stays connected for hours.
Is there any Keep Alive setting in Fortigate that can be used to prevent this from disconnecting or keep the tunnel up?
I see "allow Client to Keep Connections Alive" in the SSL VPN Portals/ Full-Access.
Does this Setting result in Caching of the user PW. In other words - if I enable this will the Client PC retain the User PW so that the device can be reconnected without permission and without requesting PW???
5.4.1 SSL VPN handbook [http://docs.fortinet.com/d/fortigate-ssl-vpn-4] says below in pp42:
"- Allow client to keep connections alive - When enabled, if the user selects this option, the FortiClient should try to reconnect once it detects the VPN connection is down unexpectedly (not manually disconnected by user)."
So it's not going to reduce droppings in your case, but it would just reconnect automatically after a drop.
Rather you want to find out why some of them drop often while others don't. We had similar issues when Antivirus/FW features were unintentionally activated at the FortiClient config file while "VPN only" was chosen for instrallation. And after that was fixed, we found (and proved, more imporantly) the connectivity over the internet from the particular client location was often degraded (dropping some packets). But try enabling local logging first and look at what's in the log at those often dropping clients.
Toshi
I have some Debug Logs from a Client that disconnects.
What am I looking for in the Log.
We are set to/ supposed to be VPN Only.
I do see 3 references to "Update Task get virus info file failed" in the Log but no other mention of Virus
Do you see any "VPN errors"?
User | Count |
---|---|
2568 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.