<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 80.40 L2TP remote access users dropped after renegotiation in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/80-40-L2TP-remote-access-users-dropped-after-renegotiation/m-p/135437#M7594</link>
    <description>&lt;P&gt;On a 77.30 standalone gateway ( using an 80.40 management server ) our L2TP remote access users could stay connected for an unlimited amount of time.&lt;/P&gt;&lt;P&gt;After upgrading the gateway to 80.40 our users are getting dropped after about 8 hours. This happens right after the renegotiation of&amp;nbsp; Phase1+phase2. I have been through all of the vpn debug logs and it looks like the renegotiation completes successfully but the connection is still dropped.&lt;/P&gt;&lt;P&gt;Has anyone found a solution to this problem in 80.40? I have been applying hotfixes as they come out and am now up to Ongoing 131.&amp;nbsp; These have fixed some issues with L2TP but not this one.&lt;/P&gt;&lt;P&gt;At the time of the drop in the firewall log i see&amp;nbsp; these 2 entries&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Id: 98610405-6120-0000-61a8-6fa200000000&lt;BR /&gt;Marker: @A@@B@1638427242@C@1277101&lt;BR /&gt;Log Server Origin: 152.x.x.x&lt;BR /&gt;Time: 2021-12-02T07:02:58Z&lt;BR /&gt;Id Generated By Indexer: false&lt;BR /&gt;First: false&lt;BR /&gt;Sequencenum: 20&lt;BR /&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: L2TP&lt;BR /&gt;Login Option: Standard&lt;BR /&gt;Failed Login Factor Number:0&lt;BR /&gt;User DN: Unknown&lt;BR /&gt;User Groups: All Users&lt;BR /&gt;Re-authentication every: 8 hours&lt;BR /&gt;Login Timestamp: 2021-12-02T07:02:58Z&lt;BR /&gt;Source: 99.125.x.x&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: IPSec&lt;BR /&gt;Methods: 3DES + SHA1&lt;BR /&gt;Status: Success&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Mobile Access Session UID: 61A86FA2-0000-0000-9861-040561200000&lt;BR /&gt;Data Encryption: 3DES + SHA1 + Group 2, Pre shared secrets&lt;BR /&gt;Last Update Time: 2021-12-02T07:02:58Z&lt;BR /&gt;Action: Log In&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Origin: fw2.sewanee.edu&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;/P&gt;&lt;P&gt;Followed by:&lt;/P&gt;&lt;P&gt;Id: 98611316-e39e-7e0f-61a8-6faab8cf0012&lt;BR /&gt;Marker: @A@@B@1638427242@C@1284570&lt;BR /&gt;Log Server Origin: 152.x.x.x&lt;BR /&gt;Time: 2021-12-02T07:03:06Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth4&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 19&lt;BR /&gt;Source: 99.125.x.x&lt;BR /&gt;Source Port: 1701&lt;BR /&gt;Destination: 152.x.x.x&lt;BR /&gt;Destination Port: 1701&lt;BR /&gt;IP Protocol: 17&lt;BR /&gt;User: &amp;lt;L2TP_machine_user&amp;gt;_10658159151012685838_1120329598916211330&lt;BR /&gt;Message: Cannot control L2TP tunnel owned by &amp;lt;L2TP_machine_user&amp;gt;_&lt;BR /&gt;VPN Feature: L2TP&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Connection&lt;BR /&gt;Policy Name: new_rules_2&lt;BR /&gt;Policy Management: cpmanage&lt;BR /&gt;Db Tag: {696A09B6-67EB-6C4D-87D7-38AD5CFF65F9}&lt;BR /&gt;Policy Date: 2021-12-01T18:12:36Z&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Origin: firewall2&lt;BR /&gt;Service: UDP/1701&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;Interface: eth4&lt;BR /&gt;Description: Cannot control L2TP tunnel owned by &amp;lt;L2TP_machine_user&amp;gt;_&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I see unusual in the vpn debug log is that on initial connection&amp;nbsp; I see HandleNatDPayloads: I am not behind a NAT!.&lt;BR /&gt;But after the renegotiation I see HandleNatDPayloads: I am behind a NAT!&lt;BR /&gt;The peer is always behind a NAT.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 22:22:46 GMT</pubDate>
    <dc:creator>Michael_Guyear</dc:creator>
    <dc:date>2021-12-02T22:22:46Z</dc:date>
    <item>
      <title>80.40 L2TP remote access users dropped after renegotiation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/80-40-L2TP-remote-access-users-dropped-after-renegotiation/m-p/135437#M7594</link>
      <description>&lt;P&gt;On a 77.30 standalone gateway ( using an 80.40 management server ) our L2TP remote access users could stay connected for an unlimited amount of time.&lt;/P&gt;&lt;P&gt;After upgrading the gateway to 80.40 our users are getting dropped after about 8 hours. This happens right after the renegotiation of&amp;nbsp; Phase1+phase2. I have been through all of the vpn debug logs and it looks like the renegotiation completes successfully but the connection is still dropped.&lt;/P&gt;&lt;P&gt;Has anyone found a solution to this problem in 80.40? I have been applying hotfixes as they come out and am now up to Ongoing 131.&amp;nbsp; These have fixed some issues with L2TP but not this one.&lt;/P&gt;&lt;P&gt;At the time of the drop in the firewall log i see&amp;nbsp; these 2 entries&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Id: 98610405-6120-0000-61a8-6fa200000000&lt;BR /&gt;Marker: @A@@B@1638427242@C@1277101&lt;BR /&gt;Log Server Origin: 152.x.x.x&lt;BR /&gt;Time: 2021-12-02T07:02:58Z&lt;BR /&gt;Id Generated By Indexer: false&lt;BR /&gt;First: false&lt;BR /&gt;Sequencenum: 20&lt;BR /&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: L2TP&lt;BR /&gt;Login Option: Standard&lt;BR /&gt;Failed Login Factor Number:0&lt;BR /&gt;User DN: Unknown&lt;BR /&gt;User Groups: All Users&lt;BR /&gt;Re-authentication every: 8 hours&lt;BR /&gt;Login Timestamp: 2021-12-02T07:02:58Z&lt;BR /&gt;Source: 99.125.x.x&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: IPSec&lt;BR /&gt;Methods: 3DES + SHA1&lt;BR /&gt;Status: Success&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Mobile Access Session UID: 61A86FA2-0000-0000-9861-040561200000&lt;BR /&gt;Data Encryption: 3DES + SHA1 + Group 2, Pre shared secrets&lt;BR /&gt;Last Update Time: 2021-12-02T07:02:58Z&lt;BR /&gt;Action: Log In&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Origin: fw2.sewanee.edu&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;/P&gt;&lt;P&gt;Followed by:&lt;/P&gt;&lt;P&gt;Id: 98611316-e39e-7e0f-61a8-6faab8cf0012&lt;BR /&gt;Marker: @A@@B@1638427242@C@1284570&lt;BR /&gt;Log Server Origin: 152.x.x.x&lt;BR /&gt;Time: 2021-12-02T07:03:06Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth4&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 19&lt;BR /&gt;Source: 99.125.x.x&lt;BR /&gt;Source Port: 1701&lt;BR /&gt;Destination: 152.x.x.x&lt;BR /&gt;Destination Port: 1701&lt;BR /&gt;IP Protocol: 17&lt;BR /&gt;User: &amp;lt;L2TP_machine_user&amp;gt;_10658159151012685838_1120329598916211330&lt;BR /&gt;Message: Cannot control L2TP tunnel owned by &amp;lt;L2TP_machine_user&amp;gt;_&lt;BR /&gt;VPN Feature: L2TP&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Connection&lt;BR /&gt;Policy Name: new_rules_2&lt;BR /&gt;Policy Management: cpmanage&lt;BR /&gt;Db Tag: {696A09B6-67EB-6C4D-87D7-38AD5CFF65F9}&lt;BR /&gt;Policy Date: 2021-12-01T18:12:36Z&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Origin: firewall2&lt;BR /&gt;Service: UDP/1701&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;Interface: eth4&lt;BR /&gt;Description: Cannot control L2TP tunnel owned by &amp;lt;L2TP_machine_user&amp;gt;_&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I see unusual in the vpn debug log is that on initial connection&amp;nbsp; I see HandleNatDPayloads: I am not behind a NAT!.&lt;BR /&gt;But after the renegotiation I see HandleNatDPayloads: I am behind a NAT!&lt;BR /&gt;The peer is always behind a NAT.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 22:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/80-40-L2TP-remote-access-users-dropped-after-renegotiation/m-p/135437#M7594</guid>
      <dc:creator>Michael_Guyear</dc:creator>
      <dc:date>2021-12-02T22:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: 80.40 L2TP remote access users dropped after renegotiation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/80-40-L2TP-remote-access-users-dropped-after-renegotiation/m-p/135482#M7595</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/22010"&gt;@Michael_Guyear&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;might be not a solution but a fix for your problem:&lt;/P&gt;&lt;P&gt;Have you increased the renegotiation time under "Global properties / Remote Access / SecureClient Mobile / Re-Authenticate user every " 1440 minutes or the time which fills your preference?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 16:12:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/80-40-L2TP-remote-access-users-dropped-after-renegotiation/m-p/135482#M7595</guid>
      <dc:creator>mhuettig</dc:creator>
      <dc:date>2021-12-03T16:12:06Z</dc:date>
    </item>
  </channel>
</rss>

