01-03-2022 05:17 AM
Hi,
We are facing issue with Global Protect VPN client connectivity for one of the user machine. Below are the details of the issue.
-> Global Protect VPN is very frequently getting disconnected
-> in Global Protect VPN connection stauts - can only see Packets Out , there are not Packets In.
In GP event logs can see "Tunnel is down due to keep-alive timeout" logs
Please let me know what can be the possible reason for GPVPN frequently disconnecting - but once connected there is no connectivity to corporate VPN over GPVPN.
Attaching the Global Protectlogs debug logs took from user n=machine during the time for issue.
Note: Issue is happening on for one user.For rest all users GPVPN is connecting fine.
05-24-2022 09:34 AM
We had this issue come up with a brand new 3410 running 10.2.1 and found a work-around. The issue is either caused by the keepalives not being sent correctly or not being detected correctly. This was causing every vpn user's connection to reset every 10min, you can imagine how happy they were. We found out is was because the gateway idle timer was set to 10min. Even though the connections were active and passing a lot of traffic the keepalives weren't being detected. We changed the idle timer to 24hrs and it fixed it as a work around. Palo support still hasn't provided any solution for this.
06-22-2022 07:51 AM
Hi,
We don't see any solution
Some private message ?
Is some one have the solution ?
For my case, the problems begun from globalprotect upgrade to 6.0.1
Thanks
Greetings
Franck
06-23-2022 12:55 PM
You have to modify the global protect gateway idle timeout to however long you want them to stay connected as a work around until Palo fixes the bug. Otherwise since it doesn't correctly detect the keepalives it will disconnect as soon as it hits the idle timeout.
06-29-2022 01:09 PM
We started having the same issue after upgrading to 10.1.6. No issue on 10.0.10.
07-22-2022 06:45 AM
We're running into the same issue. Just updated from 10.0.6 to 10.1.6 and users are being disconnected shortly after connecting to the gateway that was recently updated to 10.1.6
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!