Hey everyone 👋 I’ve been helping my team manage our FortiSASE rollout, and overall it’s been solid for our remote laptops. But we’re hitting a consistent snag with our Android field devices (mostly tablets and some phones).
The devices keep dropping off the SASE tunnel and require a full re-authentication, sometimes multiple times a day. It’s disruptive for the field teams using our real-time reporting app. We’re using SAML with Azure AD for auth, and the FortiClient is set to always-on VPN.
I checked the obvious stuff: battery optimization is disabled for FortiClient, the devices have stable internet (we tested on cellular and Wi-Fi), and we’re on the latest FortiClient version available for Android.
Has anyone else battled this? I’m wondering if there’s a specific heartbeat or keepalive setting on the FortiGate side that might be too aggressive for mobile connections, or if there’s something in the SAML token lifetime that’s clashing.
If you’ve solved this, I’d love to hear what you tweaked. Config snippets are always welcome! For example, this is the sort of thing I’ve been looking at on the FortiGate (though I’m more at home in a data pipeline config 😅):
```
config vpn ssl settings
set idle-timeout 900
set tunnel-ip-pools "SSLVPN_TUNNEL_ADDR1"
...
end
```
Could the `idle-timeout` or something in the tunnel IP pool lease be the culprit for mobile devices?
ship it
ship it
You're overcomplicating it. The always-on VPN is the problem.
Android kills persistent connections during network switches (cellular to WiFi, tower handoffs). FortiClient can't recover gracefully. Your heartbeat theory is correct, but tuning it won't fix the core issue.
Ditch the always-on tunnel for the field app. Use per-app VPN or, better yet, build proper retry logic into your reporting app with a short-lived token cache. Why force everything through a VPN when only the app needs to talk to your API?
Simplicity is the ultimate sophistication
That's a good point about network switching. But in our setup, the per-app VPN wasn't an option because the whole device needs access to internal resources for other tasks.
We still saw the drops even on a stable Wi-Fi connection, no switches. For us, extending the `auth-timeout` value on the FortiGate to 24 hours helped a lot. It seemed like the tunnel itself was staying up, but the SAML session was expiring too soon. Maybe check that?