This is a strange one. I have a bastion host running Rocky Linux 9 configured to auto logout users after 15 minutes of inactivity. When I VPN in with SSL VPN or IPSec and then login to this bastion host I am logged out after 15 minutes just as expected. However, when I setup the host so I can connect to it via ZTNA SSH Proxy the auto logout feature does not work. I have found the session still active 12+ hours latter. I do not think I created a keep alive feature any where.
Has anyone else had this issue?
Try to sniff the traffic with tcpdump from server side and see if the FGT is sending something periodically.
Maybe as @AEK mentioned if you are using Load Balancing VIP with health monitor this is happening. I see that ZTNA servers have health check option if not in the CLI but GUI:
Basic ZTNA configuration | FortiGate / FortiOS 7.4.2 | Fortinet Document Library
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.