Global protect timeout

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Global protect timeout

L4 Transporter

Here is a peculiar situation.

 

We have some field users who use their hotspot to connect to global protect. Sometimes,they  loose internet intermittantly for couple of minutes so they are being kicked out of vpn session on their machine. But in fact firewall is still having the session running on portal/gateway. They are being required to enter their credentials everytime they lose their connection while driving. they didn't have this issue when we had anyconnect before as it tries to reconnect for long time.

 

I tried increasing keepalives to 1 min but no luck. Is ther a way to tell GP clients to keep trying after losing connection until the session on portal ended?

4 REPLIES 4

L7 Applicator

Not sure about the timeout issue but one option is to set gp to always on. You can then use authentication overide and set the cookie timeout to 5 mins or longer... the gp client will try to connect and when hotspot comes back it will auto connect using the authentication cookie.

Thank you for the suggestion but my environment doesn't allow me to have always-on option. Else I prefer to do tjhat.

Ok sure... but even with gp set to on demand they would not have to enter credentials if you use overide.... just click connect, although not advisable when driving...

 

there are a few timeout settings in the gp app, have you tried them all?

 

i have never needed to use or change these options but somebody else may provide further assistance.

 

just as a side note... is there a particular reason why always on is not an option, purely for my inquisitiveness, if there is such a word.....?

 

good luck...

 

 

just upgrading to 8.8 and noticed this, it may be of some use to you,,,

it is available in some versions of 7 but may need v4 client...

 

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/res...

  • 4153 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!