- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Afternoon everyone.
Running R81.20 and will be getting everyone on Check Point Mobile VPN - 89.10.
We're seeing an issue where if a user logs into their Mobile VPN client while at home, closes their laptop lid (or doesn't disconnect from the Mobile client), then comes into the office and connects to the LAN via CAT5, the CP Mobile Access logs do not show their prior Mobile VPN session as disconnected, even though it is no longer in use. If you look at "All Users" in Tunnel & User Monitoring in SmartView Monitor, the "Stale" session does not appear. There is a disconnect between these two tools (SmartView Monitor & Logs)
Is there a way to change this behavior of the Mobile IPsec client so if a user forgets to disconnect from the VPN, their session is terminated?
Thank you!
Hey brother,
I cant find that link now I sent you some time ago, but there is guidbedit setting for disconnect on idle, if you just search disconnect_on_idle (I believe is a flag name), you can try set it to any desired value.
Thank you Andy! I had thought it was some sort of location setting...eg.. if you're connected to a LAN - disconnect any idle VPN sessions....
Not 100% sure about that, there might be, though Im not aware...
You can enforce idle client disconnection in SmartConsole in Menu - Global Properties - Remote Access - Endpoint Connect
Or check guidbedit settings that @the_rock mentioned - Idle VPN Tunnel (i think it's same setting as in SmartConsole, but with more options to set up)
Thank you @josi , thats exact setting I was referring to.
Thanks Andy! Please see my response to Josi above. I'm a bit confused over what Idle session timeout is supposed to be used for...
Thank you Josi! I'm confused about "idle session"
If I look at a user that is working from home over the Check Point Mobile client, there is constant traffic being sent back and forth, even if the user isn't accessing the internet (all web traffic goes over our VPN) or not accessing our CIFS file shares. The VPN Mobile tunnel is very chatty, constantly sending traffic back and forth with such traffic as DNS and Active Directory. What is the Idle session setting meant to be used for? For cases like in my original question where a user forgets to disconnect from their VPN client while working from home, then comes into the office within 2 hours, then connects to our corporate LAN? Or is it meant to disconnect VPN sessions when their is no traffic going over the tunnel - which in my case never happens unless a user is still connected to their Check Point VPN, then gets disconnected from their Internet connectivity?
Thank you!
Hey Joe,
I believe that would constitute for situation like this...say, for example, user locks their computer and nothing happens for 15 mins, if that value is set to 15 mins, as long as endpoint does not detect any connectivity or attempts to connect to something internal, then would disconnect the session.
Hope that helps.
Thanks again Andy!
So I understand...Check Point is "smart enough" to know when user VPN traffic is actually "accessing" resources, and not just sending "chatty" Active Directory traffic?
Do these "idle session timeout" settings, by either using guidbedit or the SmartConsolole Global settings apply to the Check Point Mobile client or just the SSL VPN?
Sorry for all the questions! I've never understood this setting and I think If I'm able to use it successfully, It could make our auditing tools Smart Console logs & "all users" in SmartView Monitor) more reliable. Currently there is a disconnect.
I believe it would apply to both, but I could be mistaken. Maybe someone else can confirm, for sure. No woirries man, happy to help.
It's not that smart... You need to exclude your "chatty" traffic (e.g. DNS, ICMP) using do_not_check_idleness_on_these_services parameter.
The idle session timeout works only on Check Point Mobile / Endpoint Security Client. SSL SNX applies only re-authentication timeout sk77380 - Can idle session timeout be configured for SNX? (or newer reference on that is here under Session Timeouts - Session Settings)
Thats true @josi . Now, I recall having to change those while back.
Hey Joe,
Please let us know once you sort this out.
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY