<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Client disconnecting every  10 to 15 minutes in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119575#M13775</link>
    <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Thank you so much for looking into this issue.&lt;BR /&gt;finally, the solution was to edit the&lt;SPAN&gt;&amp;nbsp;file $FWDIR/boot/modules/fwkern.conf and add the line:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"natt_probe_do_in_kernel=0"&lt;BR /&gt;the solution was provided in another thread: "VPN Client disconnects after one hour"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again, Thank you very much for taking your time and&amp;nbsp;for the ideas you suggested to me.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oren.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 May 2021 12:56:51 GMT</pubDate>
    <dc:creator>Oren</dc:creator>
    <dc:date>2021-05-27T12:56:51Z</dc:date>
    <item>
      <title>VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/14709#M13769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are Running R77.30 and configured Remote access vpn, Client we are using E80.65.&lt;/P&gt;&lt;P&gt;I am able to connect to successful first time but after every 10 to 15 minutes disconnecting client and saying error "VPN tunnel has disconnected and failed &amp;nbsp; to renew the encryption keys.Any idea?.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: red;"&gt;“[11 Apr 18:07:54] IKE tunnel disconnected, error code=-1000. Reason: Failed to renew Encryption keys.”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: red;"&gt;”11 Apr 18:24:52] IKE connection failed, error code=-1000. Reason: Internal error: Cannot connect to gateway: Transport failed..”&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 10:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/14709#M13769</guid>
      <dc:creator>rajesh_s</dc:creator>
      <dc:date>2018-04-12T10:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/14710#M13770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry to revive an old thread, but did you find a solution?&amp;nbsp; I am also seeing this;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; background: yellow;"&gt;[17 Nov 21:06:33] IKE tunnel disconnected, error code=-1000. Reason: Failed to renew Encryption keys.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;[17 Nov 21:06:33] Client state is connected&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; background: yellow;"&gt;[17 Nov 21:06:33] Tunnel (3) disconnected. State is connected.&amp;nbsp; cancelling connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have already followed:&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk116432 to change:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;fw ctl set int ipsec_use_p1_src_ip 1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="font-weight: 400;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;However the users ar still reporting disconnections to this specific gateway.&amp;nbsp; Others are fine....&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="font-weight: 400;"&gt;Did you manage to fix this?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="font-weight: 400;"&gt;Thanks!&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 10:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/14710#M13770</guid>
      <dc:creator>Dave_Cullen</dc:creator>
      <dc:date>2018-11-18T10:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119376#M13771</link>
      <description>&lt;P&gt;Hi Dave,&lt;BR /&gt;Are you still there?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Did you find a solution?&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 19:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119376#M13771</guid>
      <dc:creator>Oren</dc:creator>
      <dc:date>2021-05-25T19:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119462#M13772</link>
      <description>&lt;P&gt;Have you looked at&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65331&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;sk65331: Endpoint Connect disconnects after a short period of time with an error '&lt;STRONG&gt;Failed&lt;/STRONG&gt; &lt;STRONG&gt;to&lt;/STRONG&gt; &lt;STRONG&gt;renew&lt;/STRONG&gt; &lt;STRONG&gt;Encryption&lt;/STRONG&gt; &lt;STRONG&gt;keys&lt;/STRONG&gt;'&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 13:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119462#M13772</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-26T13:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119465#M13773</link>
      <description>&lt;P&gt;Hi Timothy,&lt;BR /&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;The sk65331 does not seem to meet my gateway.&lt;BR /&gt;My gateway is E80.30 and it is happening while using Windows (after 1hour) and Mac (after an hour and a half).&lt;BR /&gt;It is happening only on one of my clusters only and not on the other cluster.&lt;BR /&gt;&lt;SPAN&gt;R80.30 take 200&lt;/SPAN&gt; is the same on both of them.&lt;BR /&gt;The message after collecting logs from the client (helpdesk.log) says:&lt;BR /&gt;"IKE tunnel disconnected, error code=-1000. Reason: Failed to renew Encryption keys."&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 13:32:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119465#M13773</guid>
      <dc:creator>Oren</dc:creator>
      <dc:date>2021-05-26T13:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119504#M13774</link>
      <description>&lt;P&gt;It sounds like you are losing the IKE Phase 1 tunnel at some point, and when the IPSec/Phase 2 tunnel expires for the client (default timer for SA Lifetime is 60 minutes) they are getting kicked off because the new Phase 2 SA cannot be negotiated through the dead IKE/P1 tunnel.&amp;nbsp; Any chance that a policy reinstall happened less than 60 minutes prior to them getting disconnected?&amp;nbsp; If so try setting keep_IKE_SAs in the Global Properties.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Beyond that you will need to run a debug on vpnd and catch this failure in the act to figure out what is going on in $FWDIR/log/vpnd.elg (or just engage TAC). See&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk89940" target="_blank" rel="noopener"&gt;sk89940 - How to debug VPND daemon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also your R77.30 version is very old and unsupported so TAC may not engage.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 19:14:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119504#M13774</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-26T19:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119575#M13775</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Thank you so much for looking into this issue.&lt;BR /&gt;finally, the solution was to edit the&lt;SPAN&gt;&amp;nbsp;file $FWDIR/boot/modules/fwkern.conf and add the line:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"natt_probe_do_in_kernel=0"&lt;BR /&gt;the solution was provided in another thread: "VPN Client disconnects after one hour"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again, Thank you very much for taking your time and&amp;nbsp;for the ideas you suggested to me.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oren.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 12:56:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119575#M13775</guid>
      <dc:creator>Oren</dc:creator>
      <dc:date>2021-05-27T12:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client disconnecting every  10 to 15 minutes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119577#M13776</link>
      <description>&lt;P&gt;Interesting, thanks for the follow-up and sharing the solution.&amp;nbsp; Looks like that&amp;nbsp;&lt;SPAN&gt;natt_probe_do_in_kernel variable takes the NAT-T probing function away from the vpnd daemon and implements in the kernel/fwk instead.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 13:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-disconnecting-every-10-to-15-minutes/m-p/119577#M13776</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-27T13:07:36Z</dc:date>
    </item>
  </channel>
</rss>

