VPN disconnects spontaneously - sometimes

I set up a VPN between two Windows XP systems on two different networks, using the built-in VPN connection from XP. In most cases, the connection remains active without problem. However, on occasion, the VPN disconnects for no apparent reason. I checked the event viewer on the systems of the host and the client. The host system has no events listed in the newspapers of the Application or the system at the time when the disconnection occurred. On the client computer, the only event is an informational message in the system log: "the connection to the made by user VPNUser using VPN3-1 device has been disconnected.", the event ID is 20159. This does not really have any useful information about what happened to cause the disconnection. Are there any troubleshooting tools that I can put in place either on the host or client which may provide additional information on what causes these parasites, apparently spontaneous disconnects? Any information would be appreciated. Thank you.

A guess: this could be caused by an MTU setting that is set too high.  The maximum Transmission Unit (MTU) is usually around 1 500 bytes and includes the headers of the packets.  VPN adds additional header bytes, and if you use DSL it can be even more added bytes.  The connection works well as long as packets are exchanged, but if you start a transaction requiring large packages, you can go beyond one can suffer from the limit and the speed or the connection may be removed.  A conservative MTU when using VPN is 1300.

See this article:
"How to change MTU.
  <>http://www.howtonetworking.com/VPN/mtu1.htm >

HTH,
JW

Tags: Windows

Similar Questions

  • VPN disconnects when you switch users

    I use Windows 8 64-bit with two users. If I establish a PPTP VPN connection with a single user and then switch to another user (keeping the original logged-in user), the VPN is disconnected automatically.

    Is it possible to keep the VPN constantly connected? The computer is shared between employees who have their own office environments and disconnect the VPN cause all sorts of problems.

    Hello

    I suggest you to ask your question at the following link.

    http://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w8itpro

    I hope this helps.

  • Status SRP527w VPN disconnect button (FW:1.01.26 (003))

    Hello

    Where the disconect on the page button the VPN status went into FW:1.01.26 (003)?

    It used to be here, as you can see in the screenshots below...

    FW: 1.01.19 (004)

    FW: 1.01.26 (003)

    Hi Peter,.

    We have set in 1.1.27 - is posted the Software Center now.

    Kind regards

    Andy

  • Cisco VPN disconnection problem vpn client

    Hello

    We have a 8.2 (3) Cisco ASA and several vpn client ipsec that connect to it (5.0.07.0290 - k9 and 5.0.07.0410 - k9).

    ExExactly after that 4 hours of these clients vpn connections are deleted even if the client is still sending traffic. I can't find any parameter configuration in order to avoid this connection drop. Someone has an idea how solve it?

    I have

    I have

    AF

    Hello

    Please paste the output of "sh cry run." We can check the values of life.

    also, you can activate him debugs following like half an hour before that the Client waits for the time to unplug.

    Deb cry isa 127

    Deb cry ips 127.

    We can check the reason for the debugging by using the ip address of the client.

    I hope this helps.

    Kind regards

    Anisha

    P.S.:Please assign this thread answered if you feel that your query is resolved. Note the useful messages.

  • 4700: why my 4700 wireless disconnects spontaneously?


    Drakester;

    I have a c4780

    I looked on a HP suport page and went through a few steps, including the verification of the Configuration of the network. Everything is OK.

    What has worked so far for 72 hours, was to remove the printer in Sys Prefs and add it again.  Solution 7.

    HP has a wide web page devoted to this question: http://support.hp.com/us-en/product/hp-photosmart-c4700-all-in-one-printer-serie s/3794613/document/c02790693 /

    Thank you

  • problems with vpn firewall/proxy configuration

    Hello

    I want to access vpn through firewall/proxy (Client VPN) client-side.

    I installed the vpn gateway as firewall pix 515 using Microsoft CA IKE SA.

    I want to establish the vpn tunnel to my vpn through a proxy/firewall client.

    I tried in some places of vpn client where the firewall acts as a linux machine in which he allowed with the ipsec and NAT esp feature. Its works perfectly. But only one concurrent vpn client. Also the first tunnel vpn disconnects when the second user tries without knowing the first established tunnel.

    I heard that we can drive this problem using "NAT Taversal" mode which is available in version ios 6.3 as concentrator 3000 Cisco pix.

    I want to know how NAT Traversal can solve my problem in which multiple concurrent users without support nat esp in a configuration only one simultaneous user without support nat esp in a configuration of firewall/proxy or firewall/proxy.

    Thank you

    Karthikeyan V

    The VPN client is able to detect that he's been through a NAT/PAT device on the way to the hub/PIX, and then if both ends support it, they will automatically start NAT - T and encapsulate the IPSec packets in UDP port 4500 packets. These can then be NAT would properly and you will not get disconnections or problems you currently see.

    You don't see that a client can connect and customers being disconnected when the other connects it is your PAT instrument cannot process the ISAKMP and IPSec packets correctly. It is a fairly common symptom.

    PIX v6.3 code will support NAT - T, should be available in March sometime.

  • Juggling a 501-501 idle VPN tunnel

    Here is the config for the remote PIX 501.  I read the article that deals with 'enable or disable ISAKMP KeepAlive'.  I configured isakmp KeepAlive on the two PIX 501.  When there is no traffic, the VPN usually drops, sometimes within a few hours, sometimes within a few days.  It boils down to right upward when the remote start traffic.

    But my questions are: can I configure it to always stay up?  A missed keepalive is the origin of the tunnel to deleted?  Is this how it is 501?

    Thanks for all the comments.

    Don - pix # sh conf
    : Saved
    : Written by enable_15 at 11:42:11.280 UTC Saturday, January 2, 1993
    6.3 (5) PIX version
    interface ethernet0 car
    interface ethernet1 100full
    ethernet0 nameif outside security0
    nameif ethernet1 inside the security100
    activate the encrypted password
    encrypted passwd
    hostname don - pix
    domain name
    fixup protocol dns-length maximum 512
    fixup protocol ftp 21
    fixup protocol h323 h225 1720
    fixup protocol h323 ras 1718-1719
    fixup protocol http 80
    fixup protocol rsh 514
    fixup protocol rtsp 554
    fixup protocol sip 5060
    fixup protocol sip udp 5060
    fixup protocol 2000 skinny
    fixup protocol smtp 25
    fixup protocol sqlnet 1521
    fixup protocol tftp 69
    names of
    name xxx.xxx.xxx.xxx ocean-pix-outside
    list-access internet-traffic permit ip 192.168.1.0 255.255.255.0 any
    Allow Access-list allowed a whole icmp ping
    permit access-list toOcean-nat ip 192.168.1.0 255.255.255.0 192.168.27.0 255.255
    . 255.0
    access-list gift-to-ocean-vpn ip 10.10.3.0 allow 255.255.255.0 192.168.27.0 255.
    255.255.0
    pager lines 24
    ICMP deny everything outside
    Outside 1500 MTU
    Within 1500 MTU
    IP address outside dhcp setroute
    IP address inside 192.168.1.1 255.255.255.0
    alarm action IP verification of information
    alarm action attack IP audit
    PDM logging 100 information
    history of PDM activate
    ARP timeout 14400
    Global 1 interface (outside)
    NAT (inside) 1 list-access internet-traffic 0 0
    public static 10.10.3.0 (inside, outside) access-list toOcean-nat 0 0
    group-access allowed to ping in external interface
    Timeout xlate 0:05:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0: CPP 02:00 0:10:00 01:00 h225
    H323 timeout 0:05:00 mgcp 0: sip from 05:00 0:30:00 sip_media 0:02:00
    Sip timeout - disconnect 0:02:00 prompt Protocol sip-0: 03:00
    Timeout, uauth 0:05:00 absolute
    GANYMEDE + Protocol Ganymede + AAA-server
    AAA-server GANYMEDE + 3 max-failed-attempts
    AAA-server GANYMEDE + deadtime 10
    RADIUS Protocol RADIUS AAA server
    AAA-server RADIUS 3 max-failed-attempts
    AAA-RADIUS deadtime 10 Server
    AAA-server local LOCAL Protocol
    No snmp server location
    No snmp Server contact
    SNMP-Server Community public
    No trap to activate snmp Server
    enable floodguard
    Permitted connection ipsec sysopt
    Crypto ipsec transform-set esp ocean - esp-md5-hmac
    toOcean 20 ipsec-isakmp crypto map
    card crypto toOcean 20 match address gift-to-ocean-vpn
    card crypto toOcean 20 peers set ocean-pix-outside
    Ocean toOcean 20 transform-set card crypto
    toOcean interface card crypto outside
    ISAKMP allows outside
    ISAKMP key * address ocean-pix-outside netmask 255.255.255.255
    ISAKMP keepalive 60
    part of pre authentication ISAKMP policy 9
    encryption of ISAKMP policy 9
    ISAKMP policy 9 md5 hash
    9 2 ISAKMP policy group
    ISAKMP policy 9 life 86400
    Telnet 192.168.1.0 255.255.255.0 inside
    Telnet 192.168.27.0 255.255.255.0 inside
    Telnet timeout 30
    SSH 0.0.0.0 0.0.0.0 inside
    SSH timeout 5
    management-access inside
    Console timeout 0
    dhcpd address 192.168.1.2 - 192.168.1.33 inside
    dhcpd lease 3600
    dhcpd ping_timeout 750
    dhcpd outside auto_config
    dhcpd allow inside
    Terminal width 80
    Cryptochecksum:
    Don - pix #.

    Chris,

    I couldn't be entirely on the money here.

    But I believe that DPD is not sent, unless there is no traffic back for a period of time.

    You should have 1 missed keepalive followed by 5 aggressive testing. If your settings there should be an interruption of the connection of some 01:10 + variance

    Normally, no timeout should apply to a L2L tunnels.

    If you want to see a reason for tunnel having fallen, I'm afraid it would get debugs the disconnection.

    Marcin

  • VPN connection error - pppd limited

    Hi I think I have a problem with OX, the captain and the networks, I sail perfectly with the team but since update stops running the VPN, I tried the possibility to go to recovery mode to 'disable csrutil' then ' sudo chmod u + s / usr / sbin / pppd "but it does not work when you use Netextender or FortiClient." I have another Mac with Lion and works properly the only difference I notice in the file 'pppd' Captain makes me 'limited, compressed' and only 'compressed' Lion I put a photo and a newspaper of netextender:

    15/09/2016 10:15:59.271 [603 General info] NetExtender 8.1.788 for Mac OS X initialized

    15/09/2016 path of the bundle app NetExtender 10:15:59.299 [General info 603] = /Applications/NetExtender.app

    15/09/2016 createLogPanel() 10:16:01.045 [gui info 603]

    15/09/2016 10:16:01.730 [config info 603] loading saved profiles...

    15/09/2016 10:16:16.507 [connect info 603] user: "prueba".

    15/09/2016 10:16:16.507 [connect info 603] domain: "abcd.hos."

    15/09/2016 10:16:16.509 [connect info 603] Server: 'vpn.abcd.es:444 '.

    15/09/2016 10:16:16.581 [603 general notice] connection to vpn.abcd.es:444...

    15/09/2016 10:16:16.820 [General error 603] ERROR: SSL_connect: Undefined error: 0 (0)

    15/09/2016 10:16:16.821 [General notice 603] retry...

    15/09/2016 10:16:16.822 [General error 603] ERROR: SSL_connect: Undefined error: 0 (0)

    15/09/2016 10:16:16.823 [General error 603] authentication failed: connection failed. See the log for more details.

    15/09/2016 10:16:16.823 [General error 603] NetExtender connection failed.

    15/09/2016 10:16:16.823 [General notice 603] SSL VPN disconnect...

    15/09/2016 10:16:17.058 [General error 603] ERROR: SSL_connect: Undefined error: 0 (0)

    15/09/2016 10:16:17.058 [General notice 603] retry...

    15/09/2016 10:16:17.060 [General error 603] ERROR: SSL_connect: Undefined error: 0 (0)

    15/09/2016 10:16:17.061 [General error 603] disconnect command failed

    15/09/2016 10:16:17.063 [General notice 603] SSL VPN connection is completed.

    15/09/2016 10:16:17.063 [config info 603] loading saved profiles...

    15/09/2016 10:16:17.065 [gui info 603] connection failed. See the log for more details.

    I think that the problem is a network file or because I put the wrong password and I cannot detect this error. as I said the VPN working properly with another MAC using the same network.

    Help...

    You shouldn't be messing with the security features of the operating system.

    Problems may have to do with the network, or client software that you use.

    I start by making sure all the software are updated and then create a new entry, vpn, double control system that everything has been entered correctly.

    FWIW, I use the built-in features of VPN on El Capitan to connect to my University regularly and without problem.

    I'm not familiar with "Fortinet", and I suspect that you may need to be updated, or simply use the built-in VPN.

  • "you have been disconnected" disconnection problem

    today I tried to connect my Skype account, but I always get disconnected without reason, most of the time he's just after login, a few seconds later, I get disconnected. Sometimes it take a long time before being disconnected.

    Skype has problems right now?

    I changed my password, I have updated to the latest version (Jan.1st, 2016, 7.17.0.106) and no I don't have anything that might block the connection to the server!

    I never had any problems before, and now there's this problem.

    I use Windows 7 64-bit, latest patches and all.

    Open your Skype account setup page:

    https://secure.Skype.com/portal/account/settings

    If your Skype account is associated with the account of Microsoft, then try to separate them.

    https://support.Skype.com/en/FAQ/FA12211/how-do-i-unlink-my-Skype-and-Microsoft-or-Facebook-accounts

  • HP Officejet 8600 Pro, not connected when it is connected to a VPN

    Hello

    I'm having a problem with my HP Officejet 8600. I have a configuration of wireless network in my office, with a couple of pc and the connected printer.

    I frequently use VPN connections to my clients, as 80% of the day. The problem is that I can not print when connected to a VPN.

    Is there a work-around, except the VPN disconnection, print and sign?

    Thank you

    Henrik

    You put them on the same network (via sharing actually).  Try here for help.

    http://www.ehow.com/how_7425079_print-wireless-connection-VPN-connection.html

  • My computer is very slow and takes a long time to connect and disconnect

    Original title: sign out of questions

    My computer is very slow and takes a long time to connect and disconnect. Sometimes I hit Logoff button and do not forget I have more work to do... is it possible to cancel the newspaper once it starts, or should I just wait what he log out completely and then reconnect? (It takes just forever)

    Install the background file. See if it suits it

  • VPN connection problem: keep connection

    I'm having a problem with the maintenance of VPN connection. I connect okay but the line VPN disconnects after about 2 minutes each time.  I use XP Professional V2002, Service Pack 3.  I have disabled the WIndows firewall, as I have F-Secure software suite with its active firewall.  I connect laptop wireless via a Belkin router.  I had no problem for months up until August when suddenly this problem appeared.  I have disabled firewall F-secure, but that did not help. I also disabled the firewall on the router, but again without success.  Can you please help?

    Hi Rashmis,

    Thanks for visiting the site of the community of Microsoft Windows XP. The question you have posted is related to VPN issues and would be better suited to the Technet community. Please visit the link below to find a community that will provide the support you want. http://social.technet.Microsoft.com/forums/en/categories/

    Shawn - Support Engineer - MCP, MCDST
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Port of VPN PPTP WRT120N

    I'm trying to connect to the network through Microsoft PPTP VPN on port 1723, however when I add "Of Applications and games" on the router (chosen in the menu drop-down), it shows as port 1720 and is not connecting. If I port manually before 1723 below, it still will not connect. If I add my IP as a DMZ, it connects successfully. I started with the 1.0.04)is firmware and updated 1.0.06 and it still fails with the firmware versions and the built in PPTP definition shows like port 1720. What should I do?

    It seems to be a problem with router is. I had a problem. At home, I have a XP PC and a WRT120N. About the remote location a Draytek 2200E with active VPN server. Sometimes no VPN connection possible. WRT/off voltage switching, then possible once to configure the PPTP protocol. Second time fails. Replacing the WRT120N by an another 2200E Draytek (home side) and now everything is OK. Seems to be a bug in the software of passthough PPTP.

  • USB 3.0 drive keeps disconnecting

    System Specs:

    -Windows 7 64 bit

    -16 GB OF RAM

    All the current updates installed.

    I have a USB external drive which is new (3.0 compatible).  I plug it into the USB 3.0 port, and whenever I try to drag multiple files, it disconnects.  Sometimes it will finish copying the first file in the group, but not others.

    I have read and followed all the information in this thread:

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-hardware/USB-external-hard-drives-lose-its-connection-and/101d6422-F103-4423-95e2-718ec5146f82

    I also tried to install this hotfix:

    http://support.Microsoft.com/kb/976972

    The patch says that it is not applicable to my computer.  It is extremely annoying, because I bought a computer with the USB 3.0 primarily to transfer data increased.

    Hi dgt.mantis,

    I suggest you install the latest drivers from the chipset of the computer manufacturer's website and check if it makes a difference.

  • BACKSPACE VPN problem

    My wife works from home through a VPN for years on a Windows Vista laptop.  Since we recently moved to a new Windows 7 laptop, she began to encounter a problem while he was working in his program of VERA via their VPN connection.  Sometimes when she hits the back bar to remove a mistyped character, print the portable | brand instead.  She has to wait until something happens to expire before she can type it in again.  His work tech support staff never met this before.

    Hello

     

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    TechNet Forum

    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

     

    Hope this information helps.

Maybe you are looking for