How Inactivity Logout Triggers in GlobalProtect (updated)

How Inactivity Logout Triggers in GlobalProtect (updated)

112857
Created On 09/26/18 13:53 PM - Last Modified 08/14/26 19:47 PM


Symptom


  • GlobalProtect users are not automatically logged out after the configured "Inactivity Logout" timer expires.

  • The VPN tunnel remains active indefinitely, even when the user is away from the machine.

  • Administrators upgrading to PAN-OS 10.1 or later observe that the idle timeout behaves differently compared to PAN-OS 10.0 and earlier.



Environment


  • PAN-OS

  • GlobalProtect

  • GlobalProtect Gateway



Cause


Starting in PAN-OS 10.1, the "Inactivity Logout" timer mechanism was fundamentally changed. In PAN-OS 10.0 and earlier, this timer decremented if the Gateway failed to receive Host Information Profile (HIP) reports, which clients typically send every 60 minutes.

In PAN-OS 10.1 and later, the old HIP-based timer (was also called "Inactivity Logout") was removed. The legacy "Disconnect on Idle" timer (which is purely traffic-based) was renamed to Inactivity Logout

Pre and post PAN-OS 10.1  

 

Consequently, the timer now only expires if zero traffic passes through the VPN tunnel for the configured duration.
In this regard, something to keep in mind is that background traffic (e.g., DNS, SMB, routing protocols, 3rd party software, etc) that is routed over the tunnel resets this timer, preventing the session from naturally timing out.



Resolution


Overview

  • For PAN-OS 10.1 and later versions:
    • The "Inactivity Logout" timer is entirely traffic-based.
    • Users will be logged out of GlobalProtect only when the GlobalProtect App has not sent data traffic through the VPN tunnel for the specified amount of minutes.
    • Background operating system traffic such as DNS, routing protocols, 3rd party software, etc., can reset this timer and keep the tunnel active.
    • While the GlobalProtect client still sends the hipreportcheck.esp every hour in PAN-OS 10.1+, the firewall no longer uses it for the Inactivity Logout timer. Instead, the firewall uses that hourly HIP check to refresh the IP-to-User mapping TTL, which has a fixed lifetime of 3 hours.
  • For PAN-OS 10.0 and earlier versions:

    • Inactivity Logout can be configured under the Connection Settings tab of the GlobalProtect Gateway configuration dialogue, Network > GlobalProtect > Gateways > [Select Gateway] > Agent > Connection Settings:

    • When a user logs in with GlobalProtect, an IPSec tunnel is created. This can be seen on the CLI:
      Show session 

      Show session 
    • The time to live (TTL) value for inactivity logout refreshes once every hour, as long as the Global Protect user is logged in. This refresh occurs when the GlobalProtect client sends a hipreportcheck.esp to the firewall. Due to this behavior, the inactivity TTL will continue to decrement until it is refreshed which occurs hourly.
      > show global-protect-gateway current-user 

 

    • Verify HIP Report Check Events:
      Note: This only applies to 10.0 and earlier. For 10.1+, you can still use this command within the context of troubleshooting issues related to IP-to-User, but not issues related to Inactivity Logout.
    • Run the following command to see the hip report check event: 
      >tail follow yes webserver-log sslvpn-access.log

       

      > tail follow yes webserver-log sslvpn-access.log
    • Whether the traffic is passing or not, the tunnel will stay up unless it gets broken by a system activity, such as a PC hibernating or shutting down. In this case, the tunnel will be broken and no new hipreportcheck.esp messages will reach the Palo Alto Networks device. As a result, the Inactivity TTL will keep decrementing and will not refresh after the configured Inactivity Logout timer expires, at which point the user will be logged out.


Additional Information


Inactive GlobalProtect Sessions

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/globalprotect-features/security-policy-enforcement-for-inactive-globalprotect-sessions



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClxFCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language