<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote user gets disconnected-no reply from the gw on tunnel test packet in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175149#M5349</link>
    <description>&lt;P&gt;Yes. I was wondering if staying connected longer could maybe use more resources and cause issues but I don't think it's related.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2023 18:12:41 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2023-03-16T18:12:41Z</dc:date>
    <item>
      <title>Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174652#M5341</link>
      <description>&lt;P&gt;We have a user who keeps getting disconnected from remote VPN several times a day.&lt;/P&gt;&lt;P&gt;What I see in the helpdesk.log is entries like these:&lt;/P&gt;&lt;P&gt;[13 Mar 10:48:45] No reply from the gw ip=x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18002.&lt;/P&gt;&lt;P&gt;[13 Mar 10:48:47] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18003.&lt;/P&gt;&lt;P&gt;[13 Mar 10:48:49] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18004.&lt;/P&gt;&lt;P&gt;[13 Mar 10:48:51] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18005.&lt;/P&gt;&lt;P&gt;[13 Mar 10:48:54] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18006.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:17] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18008.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:20] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18009.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:22] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18010.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:24] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18011.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:26] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18012.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:29] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18013.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:31] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18014.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:33] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18015.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] No reply from the gw ip= x.x.x.x for tunnel test packet. Office Mode IP=10.20.9.65, source port=18016.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] Client state is connected&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] Tunnel (2) disconnected. State is connected. Trying to reconnect.&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] Client state is reconnecting&lt;/P&gt;&lt;P&gt;[13 Mar 10:49:36] Reconnect finished successfully (2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any additional places/logs I can look for indications of why it is happening? Any recommended settings that could potentially help with this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client is E86.20. Gateway is R80.40 JHF take 192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 18:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174652#M5341</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2023-03-13T18:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174656#M5342</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31256"&gt;@flachance&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some basic things I would try:&lt;/P&gt;
&lt;P&gt;1) See if you can update one or 2 clients to latest EP version (E87.20) and test&lt;/P&gt;
&lt;P&gt;2) Run packet capture on the firewall -&amp;gt; fw monitor -e "accept port(18234);"&amp;nbsp; (thats UDP port 18234, for tunnel test)&lt;/P&gt;
&lt;P&gt;3) If you know approximate time when this occurs, also run following on the fw -&amp;gt; fw ctl zdebug + drop | grep "18234" (that would tell us if anything is dropped on tunnel test port)&lt;/P&gt;
&lt;P&gt;4) Does this happen to everyone or only some folks?&lt;/P&gt;
&lt;P&gt;5) When did it start?&lt;/P&gt;
&lt;P&gt;Also, this is what TAC asked us to do when customer had this issue couple of years back (it got fixed by upgrading the cluster). Dont ask me what this option does, as no one could tell us, though it did not seem to make slightest difference (its in global properties)&lt;/P&gt;
&lt;P&gt;This is an explanation for it:&lt;/P&gt;
&lt;DIV id="mc-main-content" role="main"&gt;
&lt;P class="subheading"&gt;Back connections&lt;/P&gt;
&lt;P class="tpbodytext"&gt;Usually communication with remote clients must be initialized by the clients. However, once a client has opened a connection, the hosts behind VPN can open a return or back connection to the client. For a back connection, the client's details must be maintained on all the devices between the client and the gateway, and on the gateway itself. Determine whether the back connection is enabled, and the frequency of the Keep Alive packets sent by the client in order to maintain the connection with the gateway.&lt;/P&gt;
&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_82696647c2af7fthe_rock_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20051iC11BA7DB08B7E0CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;
&lt;P&gt;Hope that helps mate.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Mar 2023 19:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174656#M5342</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-13T19:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174880#M5343</link>
      <description>&lt;P&gt;i am having the same issue. the clients get disconnected because it could not get a response from the fw. checking the firewall logs, it shows that it is not sending the tunnel test response because "Violated unidirectional connection".&amp;nbsp; any idea why?&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have tried&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; suggestion to enable "back connections" back it didnt seem to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;also, my checkpoint firewall is behind a NAT device.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 05:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/174880#M5343</guid>
      <dc:creator>checkingout</dc:creator>
      <dc:date>2023-03-15T05:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175100#M5344</link>
      <description>&lt;P&gt;1-So I tried to upgrade the client to the latest recommended version (E86.80). It actually made things worst it fails connecting most of the time. Users has to retry 4 to 5 times before connecting successfully. We're gonna go back to 86.20 for now.&lt;/P&gt;&lt;P&gt;2-Once we're back to 86.20, I'll try some capture&lt;/P&gt;&lt;P&gt;3-It happens at random times unfortunately&lt;/P&gt;&lt;P&gt;4-No only some folks. And I can actually only find one for whom it's happening all the time. Apparently there are others but I can't get details from them. The user I'm focusing on to troubleshoot has cable internet we did a spedd test and got 63 Mbps down and 10Mbps up.&lt;/P&gt;&lt;P&gt;5-Started a few months ago. The only thing that changed near that period (that I'm aware of) is the following: We've been asked to increase the VPN re-authenticate time from 1 day to 5 days. Could this consume more resources and create this type of issue? Why only for some users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your help and suggestions&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175100#M5344</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2023-03-16T13:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175105#M5345</link>
      <description>&lt;P&gt;Im little surprised newer client made things worse, as in my experience, installing newest client version would usually help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anywho, can you run the capture I mentioned in my first response? Also, what is authentication setting changed to 5 days you are referring to? Honestly, I learned long time ago that changing any sort of timeout for those things is pretty much useless (for the lack of better word), because if you think about it logically, all thats going to do is take LONGER for things to fail, but it wont change the behavior, it will still fail at the end of the day.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:29:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175105#M5345</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T13:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175111#M5346</link>
      <description>&lt;P&gt;Im not shocked that setting did not do much for you, because even TAC could not confirm exactly what it does, apart from copying/pasting exactly what it says in the help section, but to me, its still not clear : - ). Anyway, are you seeing any traffic on port 18234 (tunnel test packets)? Do you have a log of the error mentioned?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 13:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175111#M5346</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T13:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175144#M5347</link>
      <description>&lt;P&gt;Yes, I'll start another thread with the client upgrade issue. I don't think they're related but possibly upgrading the client could help with the disconnect issue.&lt;/P&gt;&lt;P&gt;This is the re-authenticate time that was changed (I'm not sure it's related but who knows).&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 566px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20127i70C1C93272DD5272/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'll look at the capture next.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 17:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175144#M5347</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2023-03-16T17:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175148#M5348</link>
      <description>&lt;P&gt;Ah, that setting, no, that wont do a single thing here. All that does is prompts user to re-enter their password again, so they can stay connected to VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:10:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175148#M5348</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T18:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175149#M5349</link>
      <description>&lt;P&gt;Yes. I was wondering if staying connected longer could maybe use more resources and cause issues but I don't think it's related.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175149#M5349</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2023-03-16T18:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175150#M5350</link>
      <description>&lt;P&gt;Trust me, 100% its not related, I can guarantee you that.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/175150#M5350</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T18:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/204820#M5351</link>
      <description>&lt;P&gt;Have you got found a solution for the problem?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 15:40:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/204820#M5351</guid>
      <dc:creator>Homer</dc:creator>
      <dc:date>2024-02-01T15:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/205917#M5352</link>
      <description>&lt;P&gt;We never did find what was going on. One of those annoying issue that goes away after a while for which you don't exactly know what happened or changed.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 13:24:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/205917#M5352</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2024-02-13T13:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/205924#M5353</link>
      <description>&lt;P&gt;Many thanks for the answer! I've been struggling with this error for several months.&lt;BR /&gt;The latest patches are already installed.&amp;nbsp;That's why I'm still looking for a solution.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 13:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/205924#M5353</guid>
      <dc:creator>Homer</dc:creator>
      <dc:date>2024-02-13T13:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote user gets disconnected-no reply from the gw on tunnel test packet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/246068#M5354</link>
      <description>&lt;P&gt;I was experiencing the same issue and found that anti spoofing was blocking traffic between mgmt ip and office mode ip. Note: we have mdps enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 14:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-user-gets-disconnected-no-reply-from-the-gw-on-tunnel/m-p/246068#M5354</guid>
      <dc:creator>NiladriSarkar</dc:creator>
      <dc:date>2025-04-09T14:35:28Z</dc:date>
    </item>
  </channel>
</rss>

