Configure time-out settings
-
Forced time-out: If you enable this setting, NetScaler Gateway disconnects the session after the timeout interval (in minutes) elapses regardless of what the user is doing. There is no action that the user can take to prevent the disconnection from occurring when the timeout interval elapses. This setting is enforced for users who connect with the Citrix Secure Access client, Citrix Workspace app, Secure Hub, or through a web browser. The minimum value is 1 and the maximum value is 65535.
-
Session time-out: If you enable this setting, NetScaler Gateway disconnects the session if no network activity is detected for the specified interval (in minutes). This setting is enforced for users who connect with the Citrix Secure Access client, Citrix Workspace app, Citrix Secure Hub, or through a web browser. The default timeout setting is 30 minutes. The minimum value is 1 and the maximum value is 65535.
-
Idle session time-out: The duration (in minutes) after which the Citrix Secure Access™ client terminates an idle session if there is no user activity, such as from the mouse, keyboard, or touch for the specified interval. This setting is enforced for users who connect with the Citrix Secure Access client only. The minimum value is 1 and the maximum value is 9999.
-
In Always On (service mode or user mode), the VPN client ignores all the timeouts. Forced timeout and session timeout decisions occur on the NetScaler appliance and therefore those timeouts work as intended. If such timeout occurs, the VPN plug-in tries to perform automatic authentication.In Always On, as the user device must be connected via the VPN tunnel all the time, do not configure forced timeout or client idle timeout. However, session timeout can be configured to get rid of stale sessions.
-
Some applications, such as Microsoft Outlook, automatically send network traffic probes to email servers without any user intervention. Citrix® recommends that you configure Idle session time-out with session time-out to ensure that a session left unattended on a user device times out in a reasonable time.
Configure forced time-outs
Configure a global forced time-out
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Network Configuration tab, click Advanced Settings.
-
In Forced Time-out (mins), type the number of minutes users can stay connected.
-
In Forced Time-out Warning (mins), type the number of minutes before users are warned that the connection is due to be disconnected and then click OK.
Configure a forced time-out within a session policy
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session.
-
In the details pane, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
On the Network Configuration tab, click Advanced.
-
Under Timeouts, click Override Global and in Forced Time-out (mins) type the number of minutes users can stay connected.
-
Next to Forced Time-out Warning (mins), click Override Global and type the number of minutes users are warned that the connection is due to be disconnected. Click OK twice.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
Configure session or idle time-outs
To configure a session or client idle time-out globally by using the GUI
-
On the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Client Experience tab, do one or both of the following:
-
In Session Time-out (mins), type the number of minutes.
-
In Client Idle Time-out (mins), type the number of minutes and then click OK.
-
To configure session or client idle time-out settings by using a session policy by using the GUI
-
On the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session
-
In the NetScaler Gateway Session Policies and Profiles page, click Session Profiles, and then click Add.
-
In Name, type a name for the profile.
-
On the Client Experience tab, do one or both of the following:
-
Next to Session Time-out (mins), click Override Global and then type the number of minutes and then click Create.
-
Next to Client Idle Time-out (mins), click Override Global, type the number of minutes and then click Create.
-
-
-
In the NetScaler Gateway Session Policies and Profiles page, click Sessions Policies, and then click Add.
-
-
In the Create NetScaler Gateway Session Policy,
-
In Name, enter the name for the policy.
-
In Profile, select the profile that specifies the action to be applied by the new session policy if the rule criteria are met.
-
select Advanced policy.
-
In the Expression field, add your expression or name of a named expression, specifying the traffic that matches the policy.
-
Click Create, and then click Close.
-