Linux VPNC leaving duplicate connections

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Linux VPNC leaving duplicate connections

L3 Networker

Hi all,


Environment Overview:

I have a 3 PA firewalls (connected in a hub-and-spoke fashion - 2 satellites, 1 portal.   All the client VPN traffic (VPNC for Linux, GlobalProtect for Windows) is routed from the satellites to the portal to a trusted network behind the portal.  


Issue Experiencing:

When a VPNC client (call it Client-A), connects to any firewall (call them PA-1, PA-2, PA-3), the connection works just fine.  When Client-A disconnects from PA-1and connects to PA-2, the connection works from the client side.


However, if you look at the GUI for PA-1, the connection for Client-A is still there even though Client-A is not connected to PA-1 anymore.   From the firewall perspective, it is as if Client-A is connected to PA-1 and PA-2 (but in reality is only connected to PA-2).  There have been instances where these "phantom connections" are on all three firewalls, but only one connection is a real VPNC connection.


Additional Points:

- I have changed the timeout settings for the client on the firewall side, this did not fix the issue.

- This is only specific to the Linux VPNC client, there are no problems with the GlobalProtect client for Windows.


I am really stumped on this one.  ANY insight to possible starting points is much appreciated.  

  • 0 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!