<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote VPN to disconnect after 15 minutes in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130118#M8019</link>
    <description>&lt;P&gt;Yup, installed on both our VPN gateways. Let's hope this will end-up working.&lt;/P&gt;&lt;P&gt;Thanks anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 21:45:43 GMT</pubDate>
    <dc:creator>Ob1lan</dc:creator>
    <dc:date>2021-09-23T21:45:43Z</dc:date>
    <item>
      <title>Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130041#M8007</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have this new requirement from the management : we need our VPN clients to disconnect after 15 minutes of inactivity. We have both Windows and MacOS clients, using the standalone VPN clients.&lt;/P&gt;&lt;P&gt;I search and found some sk106952, explaining that we could edit the&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;$FWDIR/conf/trac_client_1.ttm &lt;/EM&gt;&lt;/STRONG&gt;file. However, the values I find on the files from my gateways are different from those explained in the SK and other documentation (sk75221).&lt;/P&gt;&lt;P&gt;What I have in my file:&lt;/P&gt;&lt;LI-CODE lang="css"&gt;:neo_disconnect_when_idle (
                        :gateway (endpoint_vpn_disconnect_when_idle
                                :default (client_decide)
                        )
                )
:neo_disconnect_when_idle_timeout (
                        :gateway (endpoint_vpn_disconnect_when_idle_timeout
                                :default (client_decide)
                        )
                )&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, which value shall I edit to make our management happy ? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 09:00:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130041#M8007</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T09:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130064#M8008</link>
      <description>&lt;P&gt;This is for&amp;nbsp;Endpoint Connect&amp;nbsp;Version&amp;nbsp;R71, R73 only -&amp;nbsp;&lt;STRONG&gt;For higher versions refer to: &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk75221" target="_blank" rel="noopener"&gt;sk75221 - Remote Access TTM Configuration&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I would suggest to open a TAC ticket...&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:11:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130064#M8008</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-23T12:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130066#M8009</link>
      <description>&lt;P&gt;Hi, thanks. That's the SK I refer too in my OP, but this doesn't contain the entries I have in my file, namely&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;neo_disconnect_when_idle
and
neo_disconnect_when_idle_timeout&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If possible I'd like to avoid going for a TAC, as it takes an awful lot of time for us to do so (we have to go first with our partner, and have them create a TAC for us).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130066#M8009</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T12:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130070#M8010</link>
      <description>&lt;P&gt;Opening a TAC case thru a CCSP takes around 20 minutes !&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:34:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130070#M8010</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-23T12:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130071#M8011</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; As I said, I'm not entitled to do that, we have to go through our partner/reseller, as the account is under their management, not ours.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130071#M8011</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T12:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130072#M8012</link>
      <description>&lt;P&gt;There is super easy solution to this, no need for TAC case brother : ). Just follow below link and look for section I pasted. I had 4 customers do this, never a problem. Dont even bother touching trac_client_1.ttm file, no need at all, just leave it as is.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/81/814f1e719db5a506a2fdd052dcc0eab9/CP_E80.50_RemoteAccessClients_forWin_AdminGuide.pdf?HashKey=1632408252_5017b7ce0847afcd053204202badc735&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/81/814f1e719db5a506a2fdd052dcc0eab9/CP_E80.50_RemoteAccessClients_forWin_AdminGuide.pdf?HashKey=1632408252_5017b7ce0847afcd053204202badc735&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To configure tunnel idleness:&lt;BR /&gt;1. Connect to the Security Management Server with GuiDBedit.&lt;BR /&gt;2. Open the Global Properties &amp;gt; properties &amp;gt; firewall_properties object.&lt;BR /&gt;3. Find disconnect_on_idle and these parameters:&lt;BR /&gt; do_not_check_idleness_on_icmp_packets&lt;BR /&gt; do_not_check_idleness_on_these_services - Enter the port numbers for the services that&lt;BR /&gt;you want to ignore when idleness is checked.&lt;BR /&gt; enable_disconnect_on_idle - to enable the feature&lt;BR /&gt; idle_timeout_in_minutes&lt;BR /&gt;4. Save and install the policy.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130072#M8012</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-23T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130108#M8013</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, thanks a lot for your answer ! I'm going to test that tonight !&lt;/P&gt;&lt;P&gt;What would you recommend for those parameters ?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; do_not_check_idleness_on_icmp_packets&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; do_not_check_idleness_on_these_services - Enter the port numbers for the services that&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;you want to ignore when idleness is checked.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks a lot !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 20:07:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130108#M8013</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T20:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130109#M8014</link>
      <description>&lt;P&gt;I never touched those...just leave them as is, though if user is tech savvy enough, they can just run continuous ping to google dns and keep the tunnel up for as long as its set in global properties. Just make sure you set to try where it says enable_disconnect_on_idle and then set minutes, push policy and thats it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 20:18:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130109#M8014</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-23T20:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130111#M8015</link>
      <description>&lt;P&gt;So I've tested it, but after 30 minutes the client is still connected. In the FW logs I see usual traffic like DNS, AD, NTP, Kerberos, etc... This happened while the laptop had no use activity, no browser open, no Slack, Teams, everything closed but the VPN client...&lt;/P&gt;&lt;P&gt;So shall I fine-tune something ? Or is there an easiest solution to achieve my goal ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130111#M8015</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T21:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130112#M8016</link>
      <description>&lt;P&gt;Not 100% sure, but I never had to change anything to make this work. I will say though it was a bit flaky with 2 customers for the first 1-2 weeks, but after that it worked fine. Can you send screenshot of changes you made in guidbedit?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130112#M8016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-23T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130114#M8017</link>
      <description>&lt;P&gt;Thanks, will keep testing. Here are the settings:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-09-23 at 23.36.08.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13779iDFE019C0F7DEDCAD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-09-23 at 23.36.08.png" alt="Screenshot 2021-09-23 at 23.36.08.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:37:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130114#M8017</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T21:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130115#M8018</link>
      <description>&lt;P&gt;That looks right. As long as you installed policy after this, thats all you really need.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130115#M8018</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-23T21:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130118#M8019</link>
      <description>&lt;P&gt;Yup, installed on both our VPN gateways. Let's hope this will end-up working.&lt;/P&gt;&lt;P&gt;Thanks anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130118#M8019</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-23T21:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN to disconnect after 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130119#M8020</link>
      <description>&lt;P&gt;Im positive it will...sadly, as you probably know, some things need time and this is one of them : - )&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 21:47:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-VPN-to-disconnect-after-15-minutes/m-p/130119#M8020</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-23T21:47:13Z</dc:date>
    </item>
  </channel>
</rss>

