Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
plupien79
New Contributor

Time limit for Forticlient Users on IP-sec VPN

We have a Forticlient EMS and are using IP-Sec VPN with entra SAML to login to the VPN.

I need to have a simple time limit that would disconnect users after 12 hours of being connected (active or not)

How can this be accomplished?

Post Connection script? Automation on Fortigate? Tagging Action in EMS?

1 Solution
sjoshi

Please refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-timeout-for-Dialup-IPSEC-VPN-Tunnel/t...

 

This is one way of re auth the user

Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459

View solution in original post

10 REPLIES 10
sjoshi
Staff
Staff

can you show the config where you have setup the time limit

Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459
plupien79

I don't have it configured. But I need to, but there doesn't seem to be any guidance on this.

 

sjoshi

You can check with below settings:-

config vpn ssl settings
    set auth-timeout 28800
end
Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459
plupien79

IP-SEC though.

sjoshi

oh ok..I will have a look for IPSEC in my lab  and let u know

Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459
sjoshi

Please refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Hard-timeout-for-Dialup-IPSEC-VPN-Tunnel/t...

 

This is one way of re auth the user

Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459
plupien79

That looks like the one that I need. I'll test it out now.

sjoshi

sure..please check and let us know the status

Salon Raj Joshi
Fortinet Certified Expert (FCX) | #NSE8-003459
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors