<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What would cause different re-auth times? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225922#M3263</link>
    <description>&lt;P&gt;K, sounds good, let us know. I have couple of labs going, R81.20 and R82, never had this issue. When connected, it always asks me to re-authenticate at 23h55 mins, which is expected, as mine is set to 24 hours re-auth in global properties.&lt;/P&gt;
&lt;P&gt;Let us know what TAC says. Maybe, just as a quick test, if you can have one of those users with the issue delete/re-create the site and try, see if that makes any difference. Not sure it will, but worth a shot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sat, 07 Sep 2024 00:36:21 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-07T00:36:21Z</dc:date>
    <item>
      <title>What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225830#M3256</link>
      <description>&lt;P&gt;We've been doing some work on our VPN configs and noticed recently that the re-auth times can randomly be 8 hours while the Global Settings are set to 20 hours.&amp;nbsp; We have been playing with upgrading to the latest versions and also changing the trac file on the gateways to use DNS for connections instead of IP every time.&amp;nbsp; Is there a known bug that would cause this?&lt;/P&gt;&lt;P&gt;We do have the SecureClient Mobile set to 480 minutes (8 hours) but these are all Endpoint Security VPN clients.&lt;/P&gt;&lt;P&gt;See screenshot... this is the same user and login but starting on 8/30 you'll start seeing random 8 hour re-auth settings.&amp;nbsp; Appreciate any help!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 00:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225830#M3256</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-06T00:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225865#M3257</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/99094"&gt;@VikingsFan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is came into my mint is the trac_client_1.ttm file&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;                :neo_user_re_auth_timeout (
                        :gateway (endpoint_vpn_user_re_auth_timeout
                                :default (client_decide)&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;I will check it, if the support.checkpoint.com will&amp;nbsp; work again.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 11:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225865#M3257</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-06T11:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225866#M3258</link>
      <description>&lt;P&gt;Actually poking around in that file right now.&amp;nbsp; It's currently set to client_decide on both old and new cluster.&amp;nbsp; The only changes we made were following this SK:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk75221" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk75221&lt;/A&gt;&amp;nbsp;and also testing different Endpoint Connect versions... E88.50 and E88.60.&lt;/P&gt;&lt;P&gt;That got me thinking though where the 'client_decide' information is stored and found that it's locally on the client under the&amp;nbsp;&lt;SPAN&gt;trac.defaults file.&amp;nbsp; Going to see if our pre-packaged file from earlier has different settings in there.&amp;nbsp; Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 11:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225866#M3258</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-06T11:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225867#M3259</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/99094"&gt;@VikingsFan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good to hear that, if you find the exact sulotion, please share with us.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And compare the trac file on both GW-s, maybe there are different (and cluster members too)&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 11:19:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225867#M3259</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-06T11:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225872#M3260</link>
      <description>&lt;P&gt;The trac.defaults file was a dead-end... I loaded previous versions of our installer and did not see any difference in them that would explain a re-auth change.&amp;nbsp; The trac file on the GWs between clusters are also similar and the only change on the old gateway was the DNS update linked above.&amp;nbsp; So back to the beginning.&lt;/P&gt;&lt;P&gt;Only real change is we're using different client versions... will keep digging.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225872#M3260</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-06T12:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225920#M3261</link>
      <description>&lt;P&gt;I could be mistaken when I say this, but IM fairly sure global properties re-auth setting would override any other setting you configure for this.&lt;/P&gt;
&lt;P&gt;Can you send screenshot of how you have this in global properties?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 00:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225920#M3261</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T00:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225921#M3262</link>
      <description>&lt;P&gt;Sure.&amp;nbsp; I've also opened a TAC case through our partner and will update my post if we find out anything.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 00:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225921#M3262</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-07T00:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225922#M3263</link>
      <description>&lt;P&gt;K, sounds good, let us know. I have couple of labs going, R81.20 and R82, never had this issue. When connected, it always asks me to re-authenticate at 23h55 mins, which is expected, as mine is set to 24 hours re-auth in global properties.&lt;/P&gt;
&lt;P&gt;Let us know what TAC says. Maybe, just as a quick test, if you can have one of those users with the issue delete/re-create the site and try, see if that makes any difference. Not sure it will, but worth a shot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 00:36:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225922#M3263</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T00:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225923#M3264</link>
      <description>&lt;P&gt;I was poking around the client logs and was looking into the trac.log file and found these lines.&amp;nbsp; Could the local settings be overriding the gateway?&amp;nbsp; In our GWs trac_client_1.ttm file we have&amp;nbsp;neo_user_re_auth_timeout set to&amp;nbsp;default (client_decide).&amp;nbsp; It's been this way forever but only when we started messing with upgrade clients and add/remove sites the 8 hour limit started popping up.&lt;/P&gt;&lt;P&gt;I'll update next week after talking to TAC unless you're familiar with this setting.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Line 43922: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Primary (2FA) ,gw NULL ,user USER 
Line 44079: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Primary (Certificate), gw NULL ,user USER 
Line 44236: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Secondary (2FA) ,gw NULL ,user USER 
Line 44392: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-VPN (Certificate), gw NULL ,user USER 
Line 44550: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Secondary (Certificate), gw NULL ,user USER 
Line 44707: [ 7396 8900][6 Sep 11:28:14][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-VPN (2FA), gw NULL ,user USER 
Line 44872: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Primary (2FA) ,gw NULL ,user USER 
Line 45029: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Primary (Certificate), gw NULL ,user USER 
Line 45186: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Secondary (2FA) ,gw NULL ,user USER 
Line 45342: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-VPN (Certificate), gw NULL ,user USER 
Line 45499: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Secondary (Certificate), gw NULL ,user USER 
Line 45656: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-VPN (2FA), gw NULL ,user USER 
Line 45814: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Primary (2FA) ,gw NULL ,user USER 
Line 45971: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Primary (Certificate), gw NULL ,user USER 
Line 46128: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 1200, because it is Gateway config variable. Scope: site COMP-Secondary (2FA) ,gw NULL ,user USER 
Line 46284: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-VPN (Certificate), gw NULL ,user USER 
Line 46441: [ 7396 8900][6 Sep 11:28:15][CONFIG_MANAGER] neo_user_re_auth_timeout return value 480, because it is Default variable. Scope: site COMP-Secondary (Certificate), gw NULL ,user USER &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 01:10:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225923#M3264</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-07T01:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225924#M3265</link>
      <description>&lt;P&gt;Here is what I would try, BUT, please back up the fw and that file. Maybe replace ttm file on gw with default one and push policy, test. Or send me the file and I can compare it to one from my working gw Sunday. R81.20 version?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 01:44:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225924#M3265</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T01:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225925#M3266</link>
      <description>&lt;P&gt;Here is something you could try, just backup current ttm file and them modify as below, install policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;:neo_user_re_auth_timeout (&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:gateway (endpoint_vpn_user_re_auth_timeout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:default (&lt;/SPAN&gt;&lt;STRONG&gt;1200&lt;/STRONG&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 02:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225925#M3266</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T02:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225931#M3267</link>
      <description>&lt;P&gt;I was thinking the same thing... will give it a try.&amp;nbsp; The "neo_user" is what was throwing me off as not being applicable... is that the old name of the VPN software?&amp;nbsp; NEO?&amp;nbsp; Will report back Monday if the change helped and also if TAC says anything.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 11:32:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225931#M3267</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-07T11:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225932#M3268</link>
      <description>&lt;P&gt;Man, I have no idea LOL. The only abbreviation I know for NEO is named executive officer, haha.&lt;/P&gt;
&lt;P&gt;Anywho, I guess in this instance it could be new? No clue : - )&lt;/P&gt;
&lt;P&gt;Let us know if that fixes it, fingers crossed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 11:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225932#M3268</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T11:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225933#M3269</link>
      <description>&lt;P&gt;Thanks again.&amp;nbsp; What I don't like is how random it is.&amp;nbsp; I just connected four times with my regular MFA type and four times with my certificate and seven times I got the 1200 minutes and one time I got the 480.&amp;nbsp; Strange.&amp;nbsp; Anyways, it's the weekend!&amp;nbsp; Will make the change and report back Monday. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 11:57:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225933#M3269</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-07T11:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225934#M3270</link>
      <description>&lt;P&gt;Thats gotta be annoying, I hear ya. One thing you can do is make that change on ttm mgmt file, BUT, then it would apply to ALL gateways, just "throwing" that out there.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 12:05:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225934#M3270</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T12:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225935#M3271</link>
      <description>&lt;P&gt;Forgot to say, dont forget to install policy after making the change in ttm file.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 12:14:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225935#M3271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-07T12:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: What would cause different re-auth times?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225952#M3272</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Happy to do remote if need be, Im sure we can figure it out together, let me know.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2024 19:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/What-would-cause-different-re-auth-times/m-p/225952#M3272</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-08T19:02:19Z</dc:date>
    </item>
  </channel>
</rss>

