<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic To be more specific, you don in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788350#M173335</link>
    <description>&lt;P&gt;To be more specific, you don't want to sit behind &amp;nbsp;service provider firewall. &amp;nbsp;If you are, they might be timing out the sessions.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Perhaps try adding a keepalive and see if that changes the behaviour. &amp;nbsp;If you are running older ASA software try:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto isakmp keepalive 10&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If it doesn't take that command perhaps try:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto isakmp nat-traversal 10&lt;/PRE&gt;</description>
    <pubDate>Wed, 20 Jan 2016 19:56:41 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-01-20T19:56:41Z</dc:date>
    <item>
      <title>Cisco VPN Client session disconnect</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788343#M173327</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;Hope you're great, I got a question about something that is happening right now. I already configure some VPN accounts but I'm noticing that if i do nothing the session disconnected me in 1 minute and 37 seconds approximately. About the timeout configuration on the groupo polciy is Unlimited and the configuration in the VPN accounts are also unlimited. Also i compare the configuration with other FW that is from the same customer and is the same so I don't understand why the session are getting disconnected. The message error that I get is the 412: the remote peer is no longer responding.&lt;/P&gt;
&lt;P&gt;One workaround that i found is that if i execute a ping to an IP that is on the Secured Routes the session it wont disconnected me but as soon as I stop the ping it take like 1 minute and i get the same message (412).&lt;/P&gt;
&lt;P&gt;Do have any idea about what else i need to configure, I'm running out of ideas.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788343#M173327</guid>
      <dc:creator>Luis Carranza</dc:creator>
      <dc:date>2019-03-12T07:08:46Z</dc:date>
    </item>
    <item>
      <title>Are you connecting through</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788344#M173329</link>
      <description>&lt;P&gt;Are you connecting through another device doing a NAT translation by chance? &amp;nbsp;I bet it is timing out the UDP session (which would also explain the ping working).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do you have a different Internet connection you could connect via to prove this is the case?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 01:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788344#M173329</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-15T01:56:37Z</dc:date>
    </item>
    <item>
      <title>Hi Phillip</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788345#M173330</link>
      <description>&lt;P&gt;Hi Phillip&lt;/P&gt;
&lt;P&gt;Thanks for the answer, well as far as I know there is no NAT translation but I'll check if I can increase the UDP session.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;About using another connection I already tried from my house and the same thing is happening.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 21:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788345#M173330</guid>
      <dc:creator>Luis Carranza</dc:creator>
      <dc:date>2016-01-19T21:35:54Z</dc:date>
    </item>
    <item>
      <title>Is the VPN head end an ASA or</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788346#M173331</link>
      <description>&lt;P&gt;Is the VPN head end an ASA or IOS router? &amp;nbsp;Does it connect directly to the Internet with an IPv4 address?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you post the related VPN config?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 22:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788346#M173331</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-19T22:02:09Z</dc:date>
    </item>
    <item>
      <title>The VPN end an ASA and it</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788347#M173332</link>
      <description>&lt;P&gt;The VPN end an ASA and it connects directly to the Internet with an IPv4 address. Do&amp;nbsp; you think that the "Global Timeouts" had anything to do with this problem, I mean maybe if I change the time it could help but I don't know.&lt;/P&gt;
&lt;P&gt;Here's some of the VPN configuration.&lt;/P&gt;
&lt;P&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;group-policy Client_Policy internal&lt;BR /&gt;group-policy Client_Policy attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 8.8.8.8&lt;BR /&gt;&amp;nbsp;vpn-simultaneous-logins 2&lt;BR /&gt;&amp;nbsp;vpn-idle-timeout none&lt;BR /&gt;&amp;nbsp;vpn-session-timeout none&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec &lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value Red_VPN&lt;BR /&gt;&amp;nbsp;default-domain none&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 22:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788347#M173332</guid>
      <dc:creator>Luis Carranza</dc:creator>
      <dc:date>2016-01-19T22:13:29Z</dc:date>
    </item>
    <item>
      <title>It wont have anything to do</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788348#M173333</link>
      <description>&lt;P&gt;It wont have anything to do with the global timeouts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there any chance you sit behind a service provider firewall?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is an IKEv1 VPN, correct?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 03:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788348#M173333</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-20T03:40:56Z</dc:date>
    </item>
    <item>
      <title>Yes this is an IKE v1 VPN.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788349#M173334</link>
      <description>&lt;P&gt;Yes this is an IKE v1 VPN.&lt;/P&gt;
&lt;P&gt;About the other thing I will try to sit behind a service provider firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another thing on the VPN client log appears the next messages&lt;/P&gt;
&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10:06:48.909&amp;nbsp; 01/20/16&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp; &amp;nbsp;CVPND/0xA3400015&lt;BR /&gt;Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=172.25.3.49, error 0&lt;BR /&gt;&lt;BR /&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10:06:49.915&amp;nbsp; 01/20/16&amp;nbsp; Sev=Warning/2&amp;nbsp;&amp;nbsp; &amp;nbsp;CVPND/0xA3400015&lt;BR /&gt;Error with call to IpHlpApi.DLL: CleanUpVASettings: Was able to delete all VA settings after all, error 0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 16:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788349#M173334</guid>
      <dc:creator>Luis Carranza</dc:creator>
      <dc:date>2016-01-20T16:17:05Z</dc:date>
    </item>
    <item>
      <title>To be more specific, you don</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788350#M173335</link>
      <description>&lt;P&gt;To be more specific, you don't want to sit behind &amp;nbsp;service provider firewall. &amp;nbsp;If you are, they might be timing out the sessions.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Perhaps try adding a keepalive and see if that changes the behaviour. &amp;nbsp;If you are running older ASA software try:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto isakmp keepalive 10&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If it doesn't take that command perhaps try:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto isakmp nat-traversal 10&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Jan 2016 19:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788350#M173335</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-20T19:56:41Z</dc:date>
    </item>
    <item>
      <title>Hi Phillip</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788351#M173336</link>
      <description>&lt;P&gt;Hi Phillip&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I will try the commands that you post and see what happen. Also I request to the area who admin the Routers to verify if maybe there's a timer or something that could be affecting this connection.&lt;/P&gt;
&lt;P&gt;I will keep you post with the results.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 21:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-session-disconnect/m-p/2788351#M173336</guid>
      <dc:creator>Luis Carranza</dc:creator>
      <dc:date>2016-01-20T21:36:54Z</dc:date>
    </item>
  </channel>
</rss>

