By default, a tunnel client session length of time is configured under Configure Realm > Configure Community >Session Termination by enabling the Limit session length to credential lifetime checkbox. Users can leave sessions idle and return to them later without having to re-authenticate. If this is a security risk in your environment, there are a couple of ways to terminate sessions and require users to re-authenticate:
Automatically: You can configure the tunnel client to prompt users to re-authenticate as soon as their credentials expire. When Limit session length to credential lifetime is selected during tunnel client configuration, sessions in a given community end and require re-authentication after the length of time specified by Client security (on the System Configuration> General Settings> Appliance Options page).
See Configuring Tunnel Client Settings for more information about configuring this option.