Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Silver
New Contributor

SSL VPN

Dear All,

 

Anyone can help my citrix session disconnecting on SSL VPN. But the VPN Connection remaining up.

 

can someone advise plz

6 REPLIES 6
emnoc
Esteemed Contributor III

Have you looked at setting your fwpolicy session timeout?

 

match a diag system session filter on  your citrix  traffic by host and look at the  sessions and count down

 

diag system session stat | list

 

You can increase the session-ttl and remonitor for improvemeny

 

config system session-ttl   config port     edit 1         set protocol 6         set timeout 9600         set start-port 893     next end

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Silver
New Contributor

Hello Emonoc,

 

Thank you for your reply. I have already increased the ttl to 14400 second still same problem. Then i decided to posted on forum

 

 

Silver
New Contributor

Dear All,

 

After some deep troubleshooting for my issues i notice now the ssl vpn disconnect and at the same time my citrix session disconnect when reconnect the citrix back. Can someone advise why my ssl vpn client keep disconnecting within 1 or 2 mins everything.

 

Thank in advance 

rwpatterson
Valued Contributor III

Is the box entering conserve mode? What size? How big a load?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

One other suggestion, do you have either client or server sde tcp-keepalives as an option? This would be a dummy packet that's sent at a predefined interval to keep the tcp-sesssions from  expiring in a firewall or pat translation.

 

just my 2 cts

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Silver
New Contributor

Dear both,

 

Thank for your reply. no conserve mode and i tested with the keep alive option and without it still same problem

 

Labels
Top Kudoed Authors