Point to Site VPN timeouts

%3CLINGO-SUB%20id%3D%22lingo-sub-78915%22%20slang%3D%22en-US%22%3EPoint%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-78915%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20I%20have%20an%20Azure%20domain%20environment(no-onprem)%20and%20have%20some%20users%20on%20a%20dissimilar%20domain%20that%20connect%20to%20it%20using%20the%20point-to-site%20VPN%20to%20access%20file%20shares.%20%26nbsp%3BThe%20site-to-site%20VPNs%20work%20fine.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%20is%20they%20get%20disconnected%20from%20the%20point-to-site%20vpns%20sporadically%20throughout%20the%20day.%20%26nbsp%3BIs%20there%20a%20timeout%20or%20setting%20I%20can%20adjust%20to%20keep%20them%20connected%20all%20the%20time%3F%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-78915%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Network%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-80348%22%20slang%3D%22en-US%22%3ERe%3A%20Point%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-80348%22%20slang%3D%22en-US%22%3E%3CP%3EI%20found%20this%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F33193.azure-always-on-vpn-point-to-site-workaround.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F33193.azure-always-on-vpn-point-to-site-workaround.aspx%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eit%20uses%20scripts%20to%20make%20the%20tunnel%20always%20on.%20It%20is%20the%20only%20solution%20i%20have%20been%20able%20to%20find%2C%20unless%20you%20want%20to%20use%20Routing%20and%20Remote%20access%20in%20a%20IaaS%20VM%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-80289%22%20slang%3D%22en-US%22%3ERe%3A%20Point%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-80289%22%20slang%3D%22en-US%22%3E%3CP%3ESorry%20I%20should%20have%20specified%20them%20as%20idle%20timeouts%2C%20yes.%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-79006%22%20slang%3D%22en-US%22%3ERe%3A%20Point%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-79006%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20the%20disconnet%20during%20idle%20periods%20or%20does%20it%20happen%20during%20use%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-78964%22%20slang%3D%22en-US%22%3ERe%3A%20Point%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-78964%22%20slang%3D%22en-US%22%3E%3CP%3EI%20appreciate%20the%20feedback%20but%20I%20don't%20think%20that's%20an%20option%20on%20the%20client%20side%2C%20there's%20no%20hardware%20that%20we%20can%20adjust%20this%20on.%20%26nbsp%3BWe%20are%20using%20Windows%207.%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-78923%22%20slang%3D%22en-US%22%3ERe%3A%20Point%20to%20Site%20VPN%20timeouts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-78923%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3Eyou%20must%20clamp%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EMSS%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bat%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3E1350%3C%2FSTRONG%3E%3CSPAN%3E.%20if%20not%20this%20could%20result%20in%20what%20you%20are%20mentioning.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3Ehave%20a%20look%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-about-vpn-devices%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E%2C%20it%20will%20show%20you%20all%20the%20settings%20that%20are%20required%20for%20Azure.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUpdate%3A%20I%20did%20not%20notice%20this%20was%20Point%20to%20Site%2C%20what%20OS%20are%20they%20running%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi I have an Azure domain environment(no-onprem) and have some users on a dissimilar domain that connect to it using the point-to-site VPN to access file shares.  The site-to-site VPNs work fine.  

 

The problem is they get disconnected from the point-to-site vpns sporadically throughout the day.  Is there a timeout or setting I can adjust to keep them connected all the time?  

6 Replies
Highlighted

you must clamp MSS at 1350. if not this could result in what you are mentioning.

have a look here, it will show you all the settings that are required for Azure.

 

Update: I did not notice this was Point to Site, what OS are they running ?

Highlighted

I appreciate the feedback but I don't think that's an option on the client side, there's no hardware that we can adjust this on.  We are using Windows 7.  

Highlighted

Is the disconnet during idle periods or does it happen during use ?

Highlighted

Sorry I should have specified them as idle timeouts, yes.  

Highlighted

I found this:

 

https://social.technet.microsoft.com/wiki/contents/articles/33193.azure-always-on-vpn-point-to-site-...

 

it uses scripts to make the tunnel always on. It is the only solution i have been able to find, unless you want to use Routing and Remote access in a IaaS VM

Highlighted

We have a similar problem where the user's connection to Azure VPN drops frequently.  At times, the user can fix the problem by rebooting his/her PC.  Other times, there is no solution.  A work-around is to have the user run the following .bat file (assumption is that user only has one RAS connection profile and one .pbk file)

 

:loop
forfiles /p %USERPROFILE%\appdata\roaming\microsoft\network\connections\cm /s /m *.pbk /c "cmd /c rasdial @FNAME /PHONEBOOK:@FILE"
timeout 30
goto loop

 

(note that the forfiles command above may be wrapped in the MSDN window.  batch file only has 4 lines.)