← Back to knowledge base
high

Troubleshooting random SSL VPN disconnections on FortiGate

Confirmed 9/16/2026

Problem

Remote SSL VPN users disconnect at unpredictable intervals and must reconnect manually. Initial FortiGate log review may show no obvious error, even when bandwidth is stable and affected users connect through different ISPs and devices.

Symptoms

SSL VPN sessions may terminate within approximately 10 minutes or remain connected for about an hour before dropping. The behavior has no consistent timing pattern, affects multiple users across different ISPs and devices, and persists even when timeout settings and session TTL values appear normal.

Environment

FortiGate with SSL VPN and FortiClient. FortiGate firmware version: null. FortiClient 7.4.3 is specifically noted as having previously exhibited connection crashes.

Root Cause

The source does not establish a confirmed cause. A possible FortiClient 7.4.3 connection-crash issue should be considered, but the FortiGate and FortiClient versions and diagnostic logs must be collected before drawing a conclusion.

Solution

  1. Record the firmware version running on the FortiGate and the version of FortiClient installed on each affected endpoint.
  2. Determine whether affected endpoints use FortiClient 7.4.3. Connection crashes have previously been observed with that release, although the source does not provide a bug ID or confirmed remediation.
  3. Review the FortiClient vpn.log file around the exact time of each disconnection.
  4. If the standard client log does not identify the failure, enable extended FortiClient debugging by following How to enable debug log in FortiClient.
  5. If endpoint diagnostics remain inconclusive, use the procedures in SSL VPN Troubleshooting and FortiGate debug SSL VPN daemon to collect FortiGate-side diagnostics.
  6. Because SSL VPN daemon debugging can be disruptive or verbose, schedule the debug collection outside normal working hours when appropriate.
  7. Correlate FortiClient and FortiGate debug timestamps with the disconnect event to determine whether the session is being terminated by the client, FortiGate, or another network component.

Verification

Monitor affected users after diagnostics or remediation and confirm that SSL VPN sessions remain connected beyond the previously observed range of approximately 10 minutes to one hour. Verify that no new connection crash or session-termination entries appear in FortiClient vpn.log, extended client debug output, or FortiGate SSL VPN daemon diagnostics.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.