Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
plupien79
New Contributor

Time limit for Forticlient Users on IP-sec VPN

We have a Forticlient EMS and are using IP-Sec VPN with entra SAML to login to the VPN.

I need to have a simple time limit that would disconnect users after 12 hours of being connected (active or not)

How can this be accomplished?

Post Connection script? Automation on Fortigate? Tagging Action in EMS?

1 Solution
sjoshi

Please refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-timeout-for-Dialup-IPSEC-VPN-Tunnel/t...

 

This is one way of re auth the user

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

10 REPLIES 10
sjoshi
Staff
Staff

can you show the config where you have setup the time limit

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
plupien79

I don't have it configured. But I need to, but there doesn't seem to be any guidance on this.

 

sjoshi

You can check with below settings:-

config vpn ssl settings
    set auth-timeout 28800
end
If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
sjoshi

FYI:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-connection-logout-after-8-hours/ta...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-timers-explanation-and-SSL-VPN-Log...

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
plupien79

IP-SEC though.

sjoshi

oh ok..I will have a look for IPSEC in my lab  and let u know

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
sjoshi

Please refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-timeout-for-Dialup-IPSEC-VPN-Tunnel/t...

 

This is one way of re auth the user

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
plupien79

That looks like the one that I need. I'll test it out now.

sjoshi

sure..please check and let us know the status

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors