we noticed that if our user used vpn connection to connect to oracl database, the client will get timed out if the session is idle for some time around 10-15 mins.
is there any settings that we can configure to prevent the idle connection from getting disconnected ???
we tested using forticlient to connect to our database servers and then leave the session open, it will get disconnect after some time.
user need to re-login again
my fortigate is FG300D and firmware 5.2.3
would changing the value in idle-timeout effect the connection ?
currently my ssl vpn idle-timeout is 600 sec.
config vpn ssl settings set idle-timeout 600 set port 4433
Yes.
Richie
NSE7
is it recommended to set the idle timeout longer than 10 mins ??
Well, set it to a value that works for you - There are no right or wrong values.
Of course there are security implications that must be considered etc.
I use the value 7200 at one client - Their client computers lock themselves after 3 idle minutes anyway, so no need to take down the vpn tunnel. Your choice completely.
Richie
NSE7
found the cause of the timed out.
recently we had some issue with high memory usage.
so opened a case with support, they recommended some session-ttl settings.
soon after the issue happened.
once i remove the settings everything becomes very stable
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.