cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2021
Views
0
Helpful
2
Replies

Cisco ASA - AnyConnect default idle timeout

Hello Experts @balaji.bandi  

I want to know what's the default idle timeout on Cisco ASA AnyConnect? and how to change it.

Also, I want to ensure that AnyConnect will disconnect every 10 hours. The goal is to make sure every user reauthenticates after 10 hours.

Please let me know how I can enforce this setting.

 

Thanks,

 

Lovejit Singh

2 Accepted Solutions

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

In practice, I seldom see vpn-idle-timeout (default = 30 minutes) drop a session unless the PC goes to sleep or is suspended.

We more commonly use the vpn-session-timeout (no default so sessions stay up indefinitely) to force the reauthentication that you mentioned wanting to do. Add a value (in minutes) and the session will display a countdown in the AnyConnect / Cisco Secure Client GUI showing the remaining time. An alert message will appear 30 minutes prior to the timeout being reached.

Both parameters are set in the group-policy section of the configuration. The same applies for both ASA- and FTD-based remote access VPN configurations.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

In practice, I seldom see vpn-idle-timeout (default = 30 minutes) drop a session unless the PC goes to sleep or is suspended.

We more commonly use the vpn-session-timeout (no default so sessions stay up indefinitely) to force the reauthentication that you mentioned wanting to do. Add a value (in minutes) and the session will display a countdown in the AnyConnect / Cisco Secure Client GUI showing the remaining time. An alert message will appear 30 minutes prior to the timeout being reached.

Both parameters are set in the group-policy section of the configuration. The same applies for both ASA- and FTD-based remote access VPN configurations.

Review Cisco Networking products for a $25 gift card