Forum Discussion

Reddy1's avatar
Reddy1
Icon for Altostratus rankAltostratus
Nov 14, 2018

VPN Reconnects with out prompting for the credentials

When the user is connected to the VPN via the Edge client, and move to a different building and once connected to the network the VPN auto-connects without prompting for the credentials again.

 

My question is what exactly provides the auto-connect feature on the APM? Does the APM look for the existing session ID and if the session exists the client reconnects automatically OR the Save password to the Memory/Disc on the connectivity profile?

 

If it is based on the existing session-id , then the time the session is considered active is based on the Inactivity Timeout value in the access-profile?

 

Thanks, Sheshank

 

1 Reply

  • Hey Reddy

    Exactly, the auto-connect feature is based upon the session. You have an Inactivity Timeout that defines how long a connection needs to be "silent" before it automatically terminates. How often the Edge Client or Network Access communicates is based upon the Session Update Threshold and Session Update Window in the Network Access configuration.

    The inactivity timeout is by default set to 900 seconds (15 minutes).

    Here are the details from the help menu in the BIG-IP system:

    Inactivity Timeout

    Specifies the inactivity timeout for the connection, in seconds. If there is no activity (defined by the Session Update Threshold and Session Update Window settings in the Network Access configuration) between the client and server within the specified threshold time, the system closes the current session. By default, the timeout is 900 seconds. However, if an inactivity timeout value is set, when server traffic exceeds the specified threshold, the inactivity timeout is reset. To disable the inactivity timeout, set the Inactivity Timeout to 0.

    Note: If you disable the inactivity timeout, a session can only be terminated by user logout, maximum session timeout, or administrator termination.

    In addition, for Web Applications, you can customize the timing for the warning message to appear for the user prior to session timeout by using the Session Timeout Guard Time setting in the webtop customization settings. The user can click a link inside the message window to reset inactivity timeout.

    You can overwrite the inactivity setting in the access profile with the session variable session.inactivity_timeout, by assigning a value to the predefined session variable Inactivity Timeout in the variable assign access policy action. If this is set in the variable assign action, it overrides the setting in the access profile.

    I hope this answers your question 🙂