Jump to content

Recommended Posts

Posted (edited)

Our Cisco ASA VPN works fine - but an odd thing happens when clients PCs go to sleep (or drop wifi briefly)

 

A successfully connected PC goes to sleep, and then once woken up the vpn client is dropped and will not reconnect (and still shows in the ASDM monitoring page)

 

However, even if you Logout the session via ASDM the client cannot connect - saying it cannot contact the server. If they wait an hour (and it seems to be pretty specific to that!) then they can reconnect again

 

I can't find a setting anywhere that would prevent reconnection within an hour - is there something that would prevent this? Even when sessions had been logged out at the ASA end as well?

 

On further investigation it appears the client ip (or ISP ip) is being added to the shun list - which has a default timeout of 60 minutes which explains the complete blocking - but why its adding client source IPs to the shun list just because it disconnects is an odd one!

Edited by Sheridan
Posted

Can you see the hold-down settings? Unsure if your ASA is like mine, but show threat-detection services has a hold-down feature, I can't force mine to break as I have turned all that off, but perhaps when the device wakes up/tries to re-establish it just fails and marks them as dodge?

Posted

I can't see that on our ASA - but it does seem that is whats happening to users on a fairly random basis - they will connect fine, and then disconnect for whatever reason (sleep, wifi drops etc) and then the ASA shuns them for 60 minutes as its seen that as a threat

 

I guess I can just disabled the 'Shun hosts detected by scanning threat' as I'm not sure how much help it is if its blocking legitimate connections

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...