Session Timeout Issue - Tunnel Active but User ID Authentication removes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Session Timeout Issue - Tunnel Active but User ID Authentication removes

L3 Networker

Dear Team,

 

We are facing an issue in VPN where in Authentication of users is removed frequently at a random time.

 

IMPACT :

 

We have created Source User base policy - Hence once a user session is timed out, browsing of the user is impacted. User needs to relogin and then can access Internet Traffic. However Tunnel is always active and only "User Authentication" gets removed.

 

1) Browsing error - When the auth of the user is removed, user web browsing traffic gets blocked.

2) Session Browser - We Seen Traffic Details

3) System Logs - we got session timeout notification

4) Traffic Logs - Showing traffic hitting deny rule.

5) URL Logs - Showing Source Users mapped to ip gets removed (Zoom Webex is ip base policy and hence traffic gets routed through that Security Policy)

 

PAN  OS Version : 9.0.7

 

Please help to resolve the issue ASAP

 

Regards

Karthikeyan Balamurugan

2 REPLIES 2

Cyber Elite
Cyber Elite

did you exclude the GP ip-pool from the user-id agent?

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

No we are not ignoring any ids. It happens at a time random time. Session gets end / terminated abruptly

  • 2292 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!