Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

SSL VPN - RDP Time outs

I am using a fortigate 200A with V3 MR7 the latest firmware. We have setup SSL VPN in web mode. Most users use SSL VPN to setup bookmarks for RDP to their desktops at work. But I get many complaints that their RDP session disconnects and they have to connect again, or sometimes they cannot reconnect. They are mainly java errors. Some java errors they get is: RDP error java.lang.ArrayIndexOutOfBoundsException Coordinate out of bounds! [OK] It happens out of the blue not when they are doing a specific thing. We are using the latest firmware. Anyone having this experience. ANy solutions for this.
10 REPLIES 10
donnat
New Contributor III

Sometime, my session RDP (applet) is disconnect... I see this problem with MR3, MR4, MR5, MR6 or MR7...

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)
Not applicable

Same problem here. We' re using MR6 P3, but it was happening with the earlier MR6 versions as well. I have quite a few users complaining about random disconnects with their RDP sessions. At first I thought it was a timeout issue, but I increased to timeout to be 30 minutes and it' s still happening well before that. The users are also active in the RDP session too, so it' s not like it' s inactivity or an idle connection. They' re all running the latest version of JRE too. I' m going to try Fortinet support.
donnat
New Contributor III

YES ! no time out ! It is a old bug ! I will test with MR7P1... but I don' t think it was corrected !!!

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)
Not applicable

I just found this too within the SSL-VPN config documentation: Setting the client authentication timeout setting The client authentication timeout setting controls how long an authenticated connection will remain connected. When this time expires, the system forces the remote client to authenticate again. For example, to change the authentication timeout to 1800 seconds, enter the following commands: config vpn ssl settings set auth-timeout 1800 end I' m going to try that with my MR6P3 Original doc: http://docs.forticare.com/fgt/archives/3.0/techdocs/FortiGate_SSL_VPN_User_Guide_01-30006-0348-20080...
Not applicable

Did the client authentication timeout setting work. Did it help with the SSL VPN timeouts
rb400
New Contributor

See http://support.fortinet.com/forum/tm.asp?m=42102&p=1&tmode=1&smode=1

 

[align=left]*auto-sig*   rb400 << FGT (v6.2.x) [/align]
[align=left]*auto-sig* rb400 << FGT (v6.2.x) [/align]
Not applicable

No, no luck with the authentication timeout settings. I have an open ticket with support to try to come up with a solution. It sounds like a lot of people are having the problem. Some are reporting success with MR7, others are saying the problems are still there. Hopefully FortiOS 4.0 is out soon. Either that or I' m going to start looking at SonicWalls SSLVPN appliance
donnat
New Contributor III

About random disconnects active JAVA RDP session... Fortinet support => Bug: 82062 " This bug has been planned to be fixed in FortiOS 4.0."

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)
TopJimmy
New Contributor

my users can stay connected all day until they hit the 8 hour limit via SSL VPN and not have any issues. I' m running MR6 Patch 3. **edit** never mind. My users and using the SSL VPN in tunnel mode. I' ll try the web mode and see what happens with the Java RDP app.
-TJ
-TJ
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors