TS Time session limit with RSA agent

Posted on 2013-12-17
Last Modified: 2014-10-28
Hi Experts,

I experiment a strange behaviour on a TS server (2003 R2) which is set to use the RSA agent. The users are disconnected of their TS session after 30 minutes of idle while the RDP-Tcp connection is directly set through tscc.msc to override user settings and disconnect from idle sessions after 18 hours only and disconnect active session after 1day. I also set the "End a disconnected session" to 1 day.

I contacted RSA and they told me that this is a Windows problem and that this can't be from RSA.

We use RSA Authentication Manager 7.1 and the Windows agent on the TS server (2003 R2)

Any idea ?

Thank you in advance for your help, best regards,
Question by:jet-info
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
LVL 64

Expert Comment

ID: 39725694
In the past, RSA also advise that their appliance does not set user session timeout values. Specific to GPO, MS has the link to the configuration (there are 3 setting namely End a disconnected session, Active session limit and Idle session limit) and the RSOP to ensure the policy is configured

Another way is to go registry to see if setting stands
1/ Goto: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\TerminalServer\WinStations\RDP-Tcp
2/ Create DWORD
3/ Name: LogonTimeout (DWORD)
4/ Value: Specifies the time in seconds – Decimal Value – 300. Hex - (12c)its 5 minutes. - 3600. Hex (e10) is 1hr
5/ Please reboot the server after adding the above key.

Author Comment

ID: 39785595
Sorry for the delay, I have to manage many networks and this problem is not in the top ten so please forgive me for the delay.
I tried all these solutions without any chance. RDP sessions still deconnect after 30 minutes... Even the registry key doesn't work!

What can I check now ?
LVL 64

Expert Comment

ID: 39787325
Wondering if this helps and if w/o RSA will the TS session still be disconnected in short while of 30mins.
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.


Author Comment

ID: 39829028
Sorry for the delay,

I let it alone since it looks like that there is no solution... :(

I tried all theses solutions without any chance.

I don't understand, the registry key is configured, the GPO also. When I run a RSOP I can see it but it doesn't work.

The TS server is on a "SBS 2011 domain", I tried to isolate it in an inheritance blocked OU, the problem persists.

Any idea ?
LVL 64

Expert Comment

ID: 39829458
It is going wild and we need to isolate the issue which can be the Windows alone. I do suggest the RSA agent in the server be removed and ascertain the session timeout does not exist with the policy set as in accordance to the discussion.

If that works to see that user are not timeout in short period, we can proceed to have the RSA agent installed and verify again. This time round the problem resurfaced and RSA support need to clarify why then.

I know it is painful to rebuild but that is also a good ways to isolate the before and after effect. Audit can be enable to trace the event but I think it is even more tedious to correlate , you can check out this post @

I do see another option (or maybe the same as we said so far but no harm re-visit it) though I am not putting too much confidence in sieving out the root cause. It suggests configuring keep-alives.

You can work around the issue by configuring RDP session timeouts manually.
This change requires a reboot
-Issue can be masked if "reconnect if connection is dropped" is set at the client. Look for many instances of users disconnecting, then immediately reconnecting to identify the issue
--Disconnect Event ID, followed by a Reconnect Event ID about 10 seconds later for the same user name (Event IDs below)
--The disconnect / reconnect can also be seen in the Event ID logs on a Remote Desktop Gateway server
-TCPIP keep alive does NOT need to be configured for the RDP keep alive to work
-The registry locations are the same for Windows Server 2003 and Windows Server 2008

Author Comment

ID: 39839266
Sorry for the delay, I don't have a lot of time for the moment...
I come back ASAP.

Author Comment

ID: 40027654
Edited the KeepAlive settings in the registry with no luck... After 30 minutes, the session is again locked...

What could it be?

Any other idea ?
LVL 64

Accepted Solution

btan earned 500 total points
ID: 40028623
Will you be able to surface more log and error message (event log and rsa side) to isolate the issue as apparently this will required more drilled in (else we hitting with trial and error which is not optimal)

Author Comment

ID: 40117428
to be continued...

Author Closing Comment

ID: 40408425
Thanks, the problem remain but what can we do more....
LVL 64

Expert Comment

ID: 40408674
if only the support can see your log and help and this matter has been dragging .. and I wished not to change to 2008 R2 though

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Ready for our next Course of the Month? Here's what's on tap for June.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question