<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Remote access-users can't connect-keep getting prompt for login in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156740#M6345</link>
    <description>&lt;P&gt;internal. Primary is from our internal domain. Secondary is our DMZ domain (non-public) and tertiary internal domain again.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2022 11:59:06 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2022-09-07T11:59:06Z</dc:date>
    <item>
      <title>VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156255#M6340</link>
      <description>&lt;P&gt;Last Monday during the evening several users had issues connecting VPN Remote Access.&lt;/P&gt;&lt;P&gt;They would enter their VPN login information and 1 minute later the pop-up for the login prompt would appear again.&lt;/P&gt;&lt;P&gt;This went on for several hours. Everything was working fine for those users during the day and it was working fine again the day after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I find what caused this and ensure it doesn’t happen again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For two of them I have a Failed Login in the logs with reason ‘Could not obtain user object. Timeout reached.’ But for the others, I’m not seeing anything that stands out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The clients are E86.20. The gateway is R80.40. The management server is R81.10 (updated from R80.40 approximately two weeks before the incident)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone has seen this issue before or has anything to suggest in where to investigate to identify the cause?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 18:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156255#M6340</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-09-01T18:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156301#M6341</link>
      <description>&lt;P&gt;If this issue went away by itself have you considered / eliminated an ISP issue or was VPN the only noted impact?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also for awareness enhancements in the E86.30 client include:&lt;/P&gt;
&lt;TABLE id="resolved2Table" class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;ESVPN-3237&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Enhancement: In the roaming feature, when a VPN client works in Hub Mode with "Exclude local network" enabled, the user now does not have to re-enter credentials in case of a short network outage.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 07:25:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156301#M6341</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-02T07:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156337#M6342</link>
      <description>&lt;P&gt;Yes I've considered the ISP. I'm aware of one user in the past with a similar issue for which the problem was fixed after he switched ISP. In this case I've got several users over at least three different regions. Of course our own ISP reports no issue...&lt;/P&gt;&lt;P&gt;Nobody has reported any other issue during that period but since it was in the evening there wasn't a lot of people working.&lt;/P&gt;&lt;P&gt;I tried using cpview -t to see if I could see anything out of the ordinary for that timeframe but all I'm getting is 'History is initializing'. I tried the troubleshooting steps of&amp;nbsp;sk101878 but it doesn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything else I can look at to see if the gateway was having issue during that period.&lt;/P&gt;&lt;P&gt;That E86.30 enhancements is great. Time to schedule an upgrade &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 12:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156337#M6342</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-09-02T12:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156683#M6343</link>
      <description>&lt;P&gt;Something else I noticed during the same timeframe is a lot of Alert logs with reason "Firewall - Domain resolving error. Check DNS configuration on the gateway (0)"&lt;/P&gt;&lt;P&gt;Not sure if this is an issue since it doesn't drop or block, it just gives an alert. But it seems like an odd message and it happened around the same time&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 17:41:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156683#M6343</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-09-06T17:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156707#M6344</link>
      <description>&lt;P&gt;Are the configured DNS servers internal or external/public ones?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 23:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156707#M6344</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-06T23:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156740#M6345</link>
      <description>&lt;P&gt;internal. Primary is from our internal domain. Secondary is our DMZ domain (non-public) and tertiary internal domain again.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 11:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156740#M6345</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-09-07T11:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156746#M6346</link>
      <description>&lt;P&gt;We had case with TAC for similar issue and once customer installed newer VPN client version (cant recall which one now, I believe e86.40), issue went away.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 12:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156746#M6346</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-07T12:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access-users can't connect-keep getting prompt for login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156835#M6347</link>
      <description>&lt;P&gt;Also the DNS servers are Windows servers 2019. Looking a some DNS logs on those servers I see entries constantly repeating.&lt;/P&gt;&lt;P&gt;"The DNS server received a bad TCP-based DNS message from 10.100.0.3. The packet was rejected or ignored. The event data contains the DNS packet."&lt;/P&gt;&lt;P&gt;That's the IP of the gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 13:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-users-can-t-connect-keep-getting-prompt-for/m-p/156835#M6347</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-09-08T13:31:49Z</dc:date>
    </item>
  </channel>
</rss>

