Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
plupien79
New Contributor

Time limit for Forticlient Users on IP-sec VPN

We have a Forticlient EMS and are using IP-Sec VPN with entra SAML to login to the VPN.

I need to have a simple time limit that would disconnect users after 12 hours of being connected (active or not)

How can this be accomplished?

Post Connection script? Automation on Fortigate? Tagging Action in EMS?

9 REPLIES 9
sjoshi
Staff
Staff

can you show the config where you have setup the time limit

Let us know if this helps.
Salon Raj Joshi
plupien79

I don't have it configured. But I need to, but there doesn't seem to be any guidance on this.

 

sjoshi

You can check with below settings:-

config vpn ssl settings
    set auth-timeout 28800
end
Let us know if this helps.
Salon Raj Joshi
plupien79

IP-SEC though.

sjoshi

oh ok..I will have a look for IPSEC in my lab  and let u know

Let us know if this helps.
Salon Raj Joshi
sjoshi

Please refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-timeout-for-Dialup-IPSEC-VPN-Tunnel/t...

 

This is one way of re auth the user

Let us know if this helps.
Salon Raj Joshi
plupien79

That looks like the one that I need. I'll test it out now.

sjoshi

sure..please check and let us know the status

Let us know if this helps.
Salon Raj Joshi
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors