- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: After the VPN client dials in for a period of ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After the VPN client dials in for a period of time, the interruption occurs automatically
Hi,Engineers, I'd like to ask you a question
After the VPN client dials in for a period of time, the connection is often interrupted about two hours later.What caused the connection to fail
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm guessing this is when the client is asking for reauthentication from the end user, which it periodically does.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If your VPN goes down every two (or several, depending on IKE time-outs) hours, check that you can still reach CRL distribution point when VPN is up.
The classic case is:
1. VPN is down. IKE is established with certificates based auth. CLR is available, tunnel goes up.
2. Once keys are expired, GWs try to re-negotiate. Auth fails because CRL is no longer available. Tunnel goes down.
3. GWs retry IKE, once tunnel is down, CRL becomes reachable again, tunnel goes up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the timeout configured in the global properties ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is the same as the screenshot you sent
Are there any other screening methods?
