SSL VPN not allowing traffic after period of time

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL VPN not allowing traffic after period of time

L3 Networker

This is my scenario:  Establish an SSL VPN connection to my network.  Start using RDP to remotely manage some of my servers.  After a undetermined period of time, I'm no longer able to establish new sessions to other servers, yet my existing sessions are running just fine.  Disconnect the VPN and Reconnect, then everything seems fine for a period of time.  Seems to do the same with my mapped drives... if I've used them I can access them. If not, then new connections are blocked.

Checking the logs on the PAN, I see no blocked traffic.

Any thoughts? Known problem?  I'm running PAN OS 4.0.5 and SSL VPN 1.3.2.

8 REPLIES 8

L6 Presenter

Is there any chance that your device has already filled the session table? This could lead to the symptoms you describe.

-Benjamin

I didn't look at the session counter each time it happens, but this can happen to me late in the evening when we have next to no users in our environment.  I will check the counters though to know for sure, but I don't think we are anywhere near maxing out the 125,000 session capabilities of the PA-2020. (failed to mention which device we have in my original posting).

Hi,

Suggest you to check if there is any threat log covering the subnet of your SSLVPN clients. Also check if you have enabled any DoS policy.

Session counter shows 302 active sessions, so that isn't the problem.

Threat log also shows nothing related to the VPN subnet.

Any other ideas?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!