Global Protect VPN frequently getting disconnected

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect VPN frequently getting disconnected

L2 Linker

Hi,

 

We are facing issue with Global Protect VPN client connectivity for one of the user machine. Below are the details of the issue.

-> Global Protect VPN is very frequently getting disconnected

-> in Global Protect VPN connection stauts - can only see Packets Out , there are not Packets In.

 

In GP event logs can see "Tunnel is down due to keep-alive timeout" logs

 

Please let me know what can be the possible reason for GPVPN frequently disconnecting - but once connected there is no connectivity to corporate VPN over GPVPN.

 

Attaching the Global Protectlogs debug logs took from user n=machine during the time for issue.

 

Note: Issue is happening on for one user.For rest all users GPVPN is connecting fine.

 

 

 

24 REPLIES 24

L1 Bithead

fixed in 10.1.7 for some models...as noted in release notes:

"(PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls only) Fixed an issue where GlobalProtect IPSec tunnels disconnected at half the inactivity logout timer value.

L1 Bithead

We are also getting timeout errors on GlobalProtect connections after upgrading to 10.1.6-h6 on our PA-3220 happening at 45 mins with the inactivity logout set to 90 mins. Which coincides with the noted fix quoted above: "fixed in 10.1.7 for some models...as noted in release notes:

"(PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls only) Fixed an issue where GlobalProtect IPSec tunnels disconnected at half the inactivity logout timer value."

 

 Increased the inactivity timeout to 1200 mins as a work around. Still waiting to see if it fixes the issue. 

L0 Member

Hi,

We are also having auto disconnection issue which happened to 25 of our workstation in office, is there a solution?

Thanks

 

Cyber Elite
Cyber Elite

Hello,

While I do not know of a solution, this is from another vendors recommendations:

  • Disable all IPv6 on the client
  • Connect with patch cable and not WiFi
  • Reboot 'home' internet routers
  • Patch 'home' internet routers

 

Hope one of these might help.

What OS version are you running on your firewall?   The issue was reportedly fixed in 10.1.7 for various models.

   Prior to that, a shutdown/power off of the firewall resolved the issue, as recommended by support.    *NOT a reboot*

 

As noted, if that is not possible to upgrade or pull the power at this time, you could increase the timeout period to double what is needed.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!