Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Abdelrahman_Khaled
New Contributor

IPSec dial-up full tunnel with FortiClient

Hello Dears,

 

I need to know if there is any solution for disconnect user or down VPN automatic when user is connected to VPN but don't make any activity it just connect to VPN.  

1 Solution
Shilpa1
Staff
Staff

Hello, 

 

******************The below is for SSL VPN***********

Yes, Fortinet FortiGate firewalls provide a feature called "idle timeout" that can automatically disconnect a user or terminate a VPN session if there is no activity detected within a specified period of time. This feature helps ensure that VPN connections are not left open indefinitely when users are not actively using them.

To configure idle timeout for VPN sessions on a FortiGate firewall, you can follow these steps:

  1. Access the FortiGate web interface and navigate to "VPN" > "IPsec" or "SSL-VPN" (depending on the type of VPN you are using).

  2. Select the VPN connection or VPN profile you want to configure idle timeout for.

  3. Look for an option related to idle timeout or session timeout. The exact location and name of this setting may vary depending on your FortiGate firmware version. For example, you may find it under the "Phase 1" or "Phase 2" settings for IPsec VPNs, or in the "Portal Settings" for SSL-VPN.

  4. Enable the idle timeout setting and specify the desired timeout value. This value determines how long the VPN session can remain idle before it is automatically disconnected or terminated.

  5. Save the configuration changes and apply them to the FortiGate.

Once the idle timeout is configured, the FortiGate will monitor VPN sessions for activity. If no activity is detected within the specified timeout period, the firewall will automatically disconnect or terminate the VPN session.

Regards,
Shilpa C P

View solution in original post

2 REPLIES 2
abarushka
Staff
Staff

Hello,

 

You may consider to disable keepalive and auto-negotiate. Please find the details by following the link below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepali...

FortiGate
Shilpa1
Staff
Staff

Hello, 

 

******************The below is for SSL VPN***********

Yes, Fortinet FortiGate firewalls provide a feature called "idle timeout" that can automatically disconnect a user or terminate a VPN session if there is no activity detected within a specified period of time. This feature helps ensure that VPN connections are not left open indefinitely when users are not actively using them.

To configure idle timeout for VPN sessions on a FortiGate firewall, you can follow these steps:

  1. Access the FortiGate web interface and navigate to "VPN" > "IPsec" or "SSL-VPN" (depending on the type of VPN you are using).

  2. Select the VPN connection or VPN profile you want to configure idle timeout for.

  3. Look for an option related to idle timeout or session timeout. The exact location and name of this setting may vary depending on your FortiGate firmware version. For example, you may find it under the "Phase 1" or "Phase 2" settings for IPsec VPNs, or in the "Portal Settings" for SSL-VPN.

  4. Enable the idle timeout setting and specify the desired timeout value. This value determines how long the VPN session can remain idle before it is automatically disconnected or terminated.

  5. Save the configuration changes and apply them to the FortiGate.

Once the idle timeout is configured, the FortiGate will monitor VPN sessions for activity. If no activity is detected within the specified timeout period, the firewall will automatically disconnect or terminate the VPN session.

Regards,
Shilpa C P

Labels
Top Kudoed Authors