Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
systemgeek
Contributor II

ZTNA SSH Proxy does not auto logout user from host

This is a strange one.  I have a bastion host running Rocky Linux 9 configured to auto logout users after 15 minutes of inactivity.  When I VPN in with SSL VPN or IPSec and then login to this bastion host I am logged out after 15 minutes just as expected.  However, when I setup the host so I can connect to it via ZTNA SSH Proxy the auto logout feature does not work.  I have found the session still active 12+ hours latter.  I do not think I created a keep alive feature any where.

 

Has anyone else had this issue?

2 REPLIES 2
AEK
SuperUser
SuperUser

Try to sniff the traffic with tcpdump from server side and see if the FGT is sending something periodically.

AEK
AEK
filiaks1
Contributor II

Maybe as @AEK  mentioned if you are using Load Balancing VIP with health monitor this is happening. I see that ZTNA servers have health check option if not in the CLI but GUI:

 

Basic ZTNA configuration | FortiGate / FortiOS 7.4.2 | Fortinet Document Library

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors