cancel
Showing results for 
Search instead for 
Did you mean: 

Random disconnects when using ESP

arnold.siroin_
Occasional Contributor

Random disconnects when using ESP

We have only a handful of users that are getting disconnects after very random times, 10 minutes, 30 minutes, etc. If I set them to use pure SSL, they do not get disconnected. Anybody have this and what did they do to fix this. I have been chasing this for awhile now.

6 REPLIES 6
Kita_
Valued Contributor

Re: Random disconnects when using ESP

Hello Arnold,

I would suggest opening a ticket with JTAC as we would need to review the NC client logs along with the IVE (event, user access and admin) logs to narrow down the issue.

My educated guess would be there is something in the route between the NC client and IVE that is resetting or dropping the UDP port (4500). We've seen this in the past when a personal router or firewall have a UDP time out set to low and started dropping connections. If possible, you can test out this theory by having the same user connect to the IVE through a different median like by-pass their personal router by connecting directly to the modem. This may help narrow down the issue from the end-user side.

Vijesh Bhat_
Occasional Contributor

Re: Random disconnects when using ESP

Arnold,

Try checking the User Access Logs.
In our case even we are getting intermittent timeouts.

There could be any of the following reasons.
1. When remote (ISP) IP address changes, if you have it configured, the session would time-out.

2. In case you have two Juniper Boxes in Active/Active mode, and if primary/secondary Authentication is being done via one box and Host Checker/Network Connect is creating tunnel via other box....session will time-out.
Vijesh Bhat_
Occasional Contributor

Re: Random disconnects when using ESP

Hie Arnold,

While going through some disconnection troubleshooting I found the following KB Article and when I followed it, it worked for me.

http://kb.pulsesecure.net/InfoCenter/index?page=content&id=KB19900

Instead of changing each user's Router config, we could change Juniper config to increase ESP re-key timeout.

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
arnold.siroin_
Occasional Contributor

Re: Random disconnects when using ESP

What exactly did you do? Did you change the D-Link setting?

Vijesh Bhat_
Occasional Contributor

Re: Random disconnects when using ESP

Dear Arnold,

I have tried by changing D-Link setting for one of the users as per the KB article above in my comment and it worked. But i believe that it won't be feasible to change this setting for so many users who must be facing this issue. We could change Juniper config to increase ESP re-key timeout.

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
arnold.siroin_
Occasional Contributor

Re: Random disconnects when using ESP

Did you try doing the re-key timer to see if that fixes it?