<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VQISA3Okta Classic EngineMulti-Factor AuthenticationAnswered2024-04-17T11:33:28.000Z2017-01-30T21:27:29.000Z2017-09-20T18:41:20.000Z
Session Timeout for VPN from OKTA - is this possible
Logging in via VPN involves MFA which is manged by OKTA. Under Security -> Policy->Legacy Policy we have a session timeout set as 2 hours. This means after 2 hours of Ideal session timeout we need to login to OKTA again or it is a session timeout for VPN to get disconnected.

 

Is it possible to manage timeout for VPN from OKTA. that is after few hours of Ideal VPN has to be disconnected - If yes, please explain.

  • Hi Abarna

    The Okta session is separate from the VPN session. I don't know of any way to control the VPN session from Okta -- you'd have to control it from the VPN side.
  • coa4y (coa4y)

    Hi Gabriel,

     

    Ok, Understood, but the factor lifetime is set to one day, is it anything to do with VPN.
  • It IS connected with the "ragent.mfa.timeout.seconds" setting in the Radius config file ... see https://support.okta.com/help/answers?id=9062A000000bmWjQAI

     

    If you use this setting then in this WAY the Okta Radius Agent sends a parameter with the Radiud NACK to TELL the VPN what the lifetime of the VPN session should be.....

     

    without this the VPN session lifetime will just be whatever default the VPN developers choose

     

    see Nouredine's answer here  https://support.okta.com/help/answers?id=9062A000000bmWjQAI
    Expand Post
This question is closed.
Loading
Session Timeout for VPN from OKTA - is this possible