<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Session timeout in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16348#M12961</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44075" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44075"&gt;Endpoint Connect client disconnects every 20 seconds after connecting successfully to VPN Gateway&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Nov 2018 04:42:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-11-15T04:42:14Z</dc:date>
    <item>
      <title>VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16347#M12960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello CM!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have strange behavior which happens unexpectedly. Some users connect to R80.10 Gateway with LoadSharing Multicast with VPN client with re-authnticate options setting on 24h but disconnected&amp;nbsp;&amp;nbsp;after 2 minutes with reason "session timeout".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="74515" alt="" class="image-1 jive-image" height="282" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74515_screen1.png" width="460" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="74550" alt="" class="image-2 jive-image" height="306" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74550_screen2.png" width="480" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give a tip, where find 120 sec timeout setting or mb something else?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2018 18:32:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16347#M12960</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-14T18:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16348#M12961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44075" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44075"&gt;Endpoint Connect client disconnects every 20 seconds after connecting successfully to VPN Gateway&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 04:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16348#M12961</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-15T04:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16349#M12962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw this SK, but I think it a little&amp;nbsp;different&lt;/P&gt;&lt;P&gt;Antispoof is set to detect only&lt;/P&gt;&lt;P&gt;I increased Maximum concurrent IKE neg, but it does not work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is&amp;nbsp;no such problem when ClusterXL was in&amp;nbsp; HA mode&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 06:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16349#M12962</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-15T06:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16350#M12963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found these lines in trac.log on client:&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:26][tunnel] [WARNING] [IkeTunnel::SendTunnelTestPkt(s)] no reply from the gw. Sending tunnel test pakcet&lt;BR /&gt;[ 97 771][15 Nov 12:47:26][tunnel] IkeTunnel::SendTunnelTestPktImpl: using sport 18005.&lt;BR /&gt;[ 97 771][15 Nov 12:47:26][tunnel] IkeTunnel::SendTunnelTestPktImpl: sending tunnel test packet from 172.30.100.102 to 10.x.x.x&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:26][tunnel] [INFO] [IkeTunnel::ReceivedEsp] (0x0x6579d20): Received Esp Packet from gw 10.x.x.x .Must be tunnel test packet&lt;BR /&gt;[ 97 771][15 Nov 12:47:26][tunnel] IPsecTunnel::ReceiveTunnelTestPkt: started&lt;BR /&gt;[ 97 771][15 Nov 12:47:26][tunnel] IPsecTunnel::ReceiveTunnelTestPkt: Received tunnel test reply&lt;BR /&gt;[ 97 771][15 Nov 12:47:26][tunnel] [INFO] [IkeTunnel::ReceivedEsp] (0x0x6579d20): Tunnel state is connected&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:28][tunnel] [WARNING] [IkeTunnel::SendTunnelTestPkt(s)] receive reply from the gw. Descheduling TunnelTestTimeout and scheduling CheckDGDTimeStamp again&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:28][tunnel] [INFO] [IkeTunnel::CheckDGDTimeStamp(s)] timeout is not reached yet. Scheduling next DGD query in 17977 ms.&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:46][tunnel] [COVERAGE] [IkeTunnel::CheckDGDTimeStamp(s)] __start__&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [INFO] [IkeTunnel::CheckDGDTimeStamp(s)] tunnel 0x0x6579d20&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] IkeTunnel::CheckDGDTimeStamp: current timestamp = I64d and DGD timestamp = I64d&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [INFO] [IkeTunnel::CheckDGDTimeStamp(s)] timeout reached. Scheduling tunnel test every 2000 ms until 20000.&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [COVERAGE] [IkeTunnel::CheckDGDTimeStamp(s)] __end__ Total:0 milliseconds.&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [COVERAGE] [IkeTunnel::SendTunnelTestPkt(s)] __start__&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [INFO] [IkeTunnel::SendTunnelTestPkt(s)] tunnel 0x0x6579d20&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [WARNING] [IkeTunnel::SendTunnelTestPkt(s)] no reply from the gw. Sending tunnel test pakcet&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] IkeTunnel::SendTunnelTestPktImpl: using sport 18006.&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] IkeTunnel::SendTunnelTestPktImpl: sending tunnel test packet from 172.30.100.102 to 10.x.x.x.&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] [COVERAGE] [IkeTunnel::SendPacket] (0x0x6579d20): __start__&lt;BR /&gt;[ 97 771][15 Nov 12:47:46][tunnel] IPsecTunnel::SendPacket: sending esp packet&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:47:48][tunnel] [WARNING] [IkeTunnel::SendTunnelTestPkt(s)] no reply from the gw. Sending tunnel test pakcet&lt;BR /&gt;[ 97 771][15 Nov 12:47:48][tunnel] IkeTunnel::SendTunnelTestPktImpl: using sport 18007.&lt;BR /&gt;[ 97 771][15 Nov 12:47:48][tunnel] IkeTunnel::SendTunnelTestPktImpl: sending tunnel test packet from 172.30.100.102 to 10.x.x.x.&lt;BR /&gt;[ 97 771][15 Nov 12:47:48][tunnel] [COVERAGE] [IkeTunnel::SendPacket] (0x0x6579d20): __start__&lt;BR /&gt;[ 97 771][15 Nov 12:47:48][tunnel] IPsecTunnel::SendPacket: sending esp packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;x10 times&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[ 97 771][15 Nov 12:48:04][tunnel] [COVERAGE] [IkeTunnel::SendPacket] (0x0x6579d20): __end__ Total:0 milliseconds.&lt;BR /&gt;[ 97 771][15 Nov 12:48:04][tunnel] [COVERAGE] [IkeTunnel::SendTunnelTestPkt(s)] __end__ Total:0 milliseconds.&lt;BR /&gt;[ 97 771][15 Nov 12:48:06][tunnel] IkeTunnel::TunnelTestTimeout: stop sending tunnel tests packets. deschedule SendTunnelTestPkt&lt;BR /&gt;[ 97 771][15 Nov 12:48:06][tunnel] IkeTunnel::TunnelTestTimeout:Tunnel is disconnected !!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 08:17:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16350#M12963</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-15T08:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16351#M12964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, all day I tried to fix this issue and and that's what I discovered:&lt;/P&gt;&lt;P&gt;when I switched off Implied rules "Accept Control Connections" and write my own rule for tunnel_test port everything works fine. But when I turn everything back - "sessions timeouts" returned&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 11:35:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16351#M12964</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-15T11:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16352#M12965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;commented&amp;nbsp;/* #define ENABLE_TUNNEL_TEST */ in&amp;nbsp;implied_rules.def and added explicit rule in policy&lt;/P&gt;&lt;P&gt;We'll see what it makes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 12:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16352#M12965</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-15T12:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16353#M12966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nah, does not work(&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 18:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16353#M12966</guid>
      <dc:creator>Anton_Kazantsev</dc:creator>
      <dc:date>2018-11-15T18:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Session timeout</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16354#M12967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recommed getting the TAC involved&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 19:04:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Session-timeout/m-p/16354#M12967</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-15T19:04:29Z</dc:date>
    </item>
  </channel>
</rss>

