[vpn-help] ScreenOS XAuth problem

Matthew Grooms mgrooms at shrew.net
Mon Aug 23 23:18:01 CDT 2010


On 8/20/2010 5:44 AM, Stefan Stefanov wrote:
>
>
> Hello,
>
> I'm experiencing from time to time (less frequently since I upgraded to
> 6.3.0r4.0 from 6.3.0r3.0) user authentication errors when connecting to
> my ISG-2000 with Shrew. I tried all possible versions - alfa, beta,
> gama, stable, etc. - problem persists. This occurs especially when you
> have a bad Internet connection like mine at home and traffic drops/IKE
> timeouts occur. Has anyone experienced such issue? It's not something
> fatal but requires a firewall reset to get it fixed which is pretty
> annoying.
>

Hi Stefan,

Do you have DPD ( Dead Peer Detection ) enabled on both the gateway and 
the client? If so, the peer should clean up any lingering SA's when the 
client is disconnected due to dropped packets.

-Matthew



More information about the vpn-help mailing list