<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Avoid idle timeout of VPN session on endpoint remote access VPN client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Avoid-idle-timeout-of-VPN-session-on-endpoint-remote-access-VPN/m-p/127835#M8138</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there any further required steps (than the configuration described below) to establish always-on VPN connection from an endpoint client when the Windows' user session is locked after a certain time?&lt;/P&gt;
&lt;P&gt;Configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Endpoint version: &lt;STRONG&gt;E84.40&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Authentication by certificate&lt;/LI&gt;
&lt;LI&gt;Global Properties - connect mode at &lt;EM&gt;Always connect&lt;/EM&gt;
&lt;UL&gt;
&lt;LI&gt;which is confirmed on the client side: "always connected" is checked and greyed&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;save_cli_credentials_for_ATM&lt;/STRONG&gt; at &lt;EM&gt;true&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;automatic_capi_reauthentication&lt;/STRONG&gt; at &lt;EM&gt;true&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Errors:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:51][TR_EVENTS] TR_EVENTS::Raise: No registered cbs for event 2153254&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SEC_ASSOC] IkeSecAssoc::Timeout:SA with cookies = 44e58930ccbccb4b 25f3509dd3ee99d0 is calling its SAExpiryHandler - needs to be killed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SA_DB] Adding SA for cookies:&amp;nbsp; 44e58930ccbccb4b 25f3509dd3ee99d0&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SA_DB] ClientSADB::remove : , removed from the ClientSADB&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE] IkeTunnel::IkeSAExpired: removed SA with Cookies = 44e58930ccbccb4b 25f3509dd3ee99d0&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][rais] [DEBUG] [RaisMessages::CreateMessageSet(s)] message: (msg_obj&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :format (1.0)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :id (ClipsMessagesAuthExpired)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :def_msg ("Authentication expired")&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :arguments ()&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;…&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthenticationManager::AbortAuthRequest: __start__ 22:29:53.280&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrCredKey::TrCredKey: creating credKey&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthCache::GetSiteAuthReq: entering - item (gw = &amp;lt;GW name&amp;gt;, authMethod=certificate, realmId=vpn_Personal_Certificate)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TR_AUTH_MANAGER::TrAuthenticationManager::AbortAuthRequest: Failed to find request to abort, (gw = &amp;lt;GW name&amp;gt;, authMethod=certificate, realmId=vpn_Personal_Certificate)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthenticationManager::AbortAuthRequest: __end__ 22:29:53.280. Total time - 0 milliseconds&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_FLOW_STEP] TR_FLOW_STEP::TrConnEngineConnectStep::Cancel: Sending disconnect to GW&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][tunnel] IkeV1Tunnel::cancel_connect: started&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][tunnel] IkeV1Tunnel::notifyGwSADeletion: started&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2021 13:13:00 GMT</pubDate>
    <dc:creator>XavierBens</dc:creator>
    <dc:date>2021-08-24T13:13:00Z</dc:date>
    <item>
      <title>Avoid idle timeout of VPN session on endpoint remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Avoid-idle-timeout-of-VPN-session-on-endpoint-remote-access-VPN/m-p/127835#M8138</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there any further required steps (than the configuration described below) to establish always-on VPN connection from an endpoint client when the Windows' user session is locked after a certain time?&lt;/P&gt;
&lt;P&gt;Configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Endpoint version: &lt;STRONG&gt;E84.40&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Authentication by certificate&lt;/LI&gt;
&lt;LI&gt;Global Properties - connect mode at &lt;EM&gt;Always connect&lt;/EM&gt;
&lt;UL&gt;
&lt;LI&gt;which is confirmed on the client side: "always connected" is checked and greyed&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;save_cli_credentials_for_ATM&lt;/STRONG&gt; at &lt;EM&gt;true&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;automatic_capi_reauthentication&lt;/STRONG&gt; at &lt;EM&gt;true&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Errors:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:51][TR_EVENTS] TR_EVENTS::Raise: No registered cbs for event 2153254&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SEC_ASSOC] IkeSecAssoc::Timeout:SA with cookies = 44e58930ccbccb4b 25f3509dd3ee99d0 is calling its SAExpiryHandler - needs to be killed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SA_DB] Adding SA for cookies:&amp;nbsp; 44e58930ccbccb4b 25f3509dd3ee99d0&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE_SA_DB] ClientSADB::remove : , removed from the ClientSADB&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][IKE] IkeTunnel::IkeSAExpired: removed SA with Cookies = 44e58930ccbccb4b 25f3509dd3ee99d0&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:52][rais] [DEBUG] [RaisMessages::CreateMessageSet(s)] message: (msg_obj&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :format (1.0)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :id (ClipsMessagesAuthExpired)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :def_msg ("Authentication expired")&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :arguments ()&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;…&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthenticationManager::AbortAuthRequest: __start__ 22:29:53.280&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrCredKey::TrCredKey: creating credKey&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthCache::GetSiteAuthReq: entering - item (gw = &amp;lt;GW name&amp;gt;, authMethod=certificate, realmId=vpn_Personal_Certificate)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TR_AUTH_MANAGER::TrAuthenticationManager::AbortAuthRequest: Failed to find request to abort, (gw = &amp;lt;GW name&amp;gt;, authMethod=certificate, realmId=vpn_Personal_Certificate)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_AUTH_MANAGER] TrAuthenticationManager::AbortAuthRequest: __end__ 22:29:53.280. Total time - 0 milliseconds&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][TR_FLOW_STEP] TR_FLOW_STEP::TrConnEngineConnectStep::Cancel: Sending disconnect to GW&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][tunnel] IkeV1Tunnel::cancel_connect: started&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" size="2"&gt;[ 7516 7624][23 Aug 22:29:53][tunnel] IkeV1Tunnel::notifyGwSADeletion: started&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 13:13:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Avoid-idle-timeout-of-VPN-session-on-endpoint-remote-access-VPN/m-p/127835#M8138</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2021-08-24T13:13:00Z</dc:date>
    </item>
  </channel>
</rss>

