Hello,
I have been having an issue where our Mobile Access VPN clients will disconnect and reconnect intermittently many times a day. The Gateways are clustered active/standby CheckPoint 15400 appliances running R80.40 take 87 and the VPN clients are on version E84.50. The clients connect using machine certificate based authentication automatically. When the VPN disconnects it will automatically reconnect straight away and continue to work for a period of time before disconnecting again. In the client helpdesk log I can see the following messages:
[6 Aug 7:42:19] Starting connect...
[6 Aug 7:42:19] Creating primary conn flow to FAKE-CLUSTER-NAME (2)
[6 Aug 7:42:19] Transport is auto detect
[6 Aug 7:42:19] No need to upgrade client, client version is 986102502
[6 Aug 7:42:19] Starting new connection (2)
[6 Aug 7:42:20] No need to download topology
[6 Aug 7:42:20] No need to upgrade client, client version is 986102502
[6 Aug 7:42:20] no need executing firewall step
[6 Aug 7:42:23] Office mode IP was set successfully
[6 Aug 7:42:23] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18001.
[6 Aug 7:42:26] OM started successfully with IP = xx.xx.xx.xx.
[6 Aug 7:42:26] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18002.
[6 Aug 7:42:26] Client state is connecting
[6 Aug 7:42:26] Connection was successfully established (2)
[6 Aug 7:43:17] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18004.
[6 Aug 7:43:19] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18005.
[6 Aug 7:43:21] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18006.
[6 Aug 7:43:23] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18007.
[6 Aug 7:43:25] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18008.
[6 Aug 7:43:27] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18009.
[6 Aug 7:43:29] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18010.
[6 Aug 7:43:31] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18011.
[6 Aug 7:43:33] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=xx.xx.xx.xx, source port=18012.
[6 Aug 7:43:35] IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.
[6 Aug 7:43:35] Client state is connected
[6 Aug 7:43:35] Tunnel (2) disconnected. State is connected. Trying to reconnect.
[6 Aug 7:43:49] IKE connection failed, error code=-1000. Reason: Site is not responding.
Control connections are disabled and a Global policy is being used to allow this type of traffic. I can see that traffic is being allowed and not being blocked. I have been through SK106853 to add a NAT rule as the VPND is listening on the inside interface. The client PC is running Windows 10 with no other local firewalls blocking this traffic.
Does anyone have any suggestions as to what could be causing this issue?
Thank you.