SSL VPN not allowing traffic after period of time

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL VPN not allowing traffic after period of time

L3 Networker

This is my scenario:  Establish an SSL VPN connection to my network.  Start using RDP to remotely manage some of my servers.  After a undetermined period of time, I'm no longer able to establish new sessions to other servers, yet my existing sessions are running just fine.  Disconnect the VPN and Reconnect, then everything seems fine for a period of time.  Seems to do the same with my mapped drives... if I've used them I can access them. If not, then new connections are blocked.

Checking the logs on the PAN, I see no blocked traffic.

Any thoughts? Known problem?  I'm running PAN OS 4.0.5 and SSL VPN 1.3.2.

8 REPLIES 8

L6 Presenter

Is there any chance that your device has already filled the session table? This could lead to the symptoms you describe.

-Benjamin

I didn't look at the session counter each time it happens, but this can happen to me late in the evening when we have next to no users in our environment.  I will check the counters though to know for sure, but I don't think we are anywhere near maxing out the 125,000 session capabilities of the PA-2020. (failed to mention which device we have in my original posting).

Hi,

Suggest you to check if there is any threat log covering the subnet of your SSLVPN clients. Also check if you have enabled any DoS policy.

Session counter shows 302 active sessions, so that isn't the problem.

Threat log also shows nothing related to the VPN subnet.

Any other ideas?

Hi,

If you have any DoS policy or threat prevention settings binding to the policy that SSL traffic will hit better try to disable it for troubleshooting purpose. If it sitll cannot help I will recommend you to open a support case so that we can look into it in more details, and review your config and logs.

hello,

i have exactly the same problem. Did you have solved the problem?

Can you describe how?

Thanks.

my custoemr complains the same problem, as well.

Walter Doria

L3 Networker

The problem has gone away since moving to v4.1 on the firewall and using the new GlobalConnect VPN client (in this version, the SSL client no longer exists).

I suspect it is a bug in the old system but doubt it would be fixed as the old stuff is, well, old.

  • 4355 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!