GlobalProtect fails to restore the VPN tunnel after resuming from sleep due to Windows modern standby.

GlobalProtect fails to restore the VPN tunnel after resuming from sleep due to Windows modern standby.

37282
Created On 09/01/21 16:24 PM - Last Modified 03/11/25 05:53 AM


Symptom


  • GlobalProtect fails to restore the VPN tunnel after resuming from sleep or unlocking the device.
  • GlobalProtect prompts for re-authentication after resuming from sleep or unlocking the device (Connect method: Always-On).
The PanGPS logs below are during the time the machine was locked/sleep. 
(T3900)Debug( 550): 07/23/20 09:03:13:294 Network is reachable 
(T3900)Debug( 111): 07/23/20 09:03:13:294 connect failed with error 10065(A socket operation was attempted to an unreachable host.) 
(T3900)Debug( 599): 07/23/20 09:03:13:294 Failed to connect to 192.168.10.10 on 4501 with return value -1 and socket error 10065(A socket operation was attempted to an unreachable host.)
(T3900)Info ( 174): 07/23/20 09:03:13:294 failed to connect to ipsec : 192.168.10.10 [4501]
(T3900)Info ( 321): 07/23/20 09:03:13:294 Connecting to 192.168.10.10 failed
(T3900)Debug( 651): 07/23/20 09:03:13:294 Retry connect failed first time     
(T3900)Debug( 550): 07/23/20 09:03:15:303 Network is reachable
(T3900)Debug( 166): 07/23/20 09:03:15:305 Trying to do ipsec connection to 192.168.10.10 [4501]
(T3900)Debug( 550): 07/23/20 09:03:15:310 Network is reachable
(T3900)Debug( 111): 07/23/20 09:03:15:310 connect failed with error 10065(A socket operation was attempted to an unreachable host.)
(T3900)Debug( 599): 07/23/20 09:03:15:310 Failed to connect to 192.168.10.10 on 4501 with return value -1 and socket error 10065(A socket operation was attempted to an unreachable host.)
(T3900)Info ( 174): 07/23/20 09:03:15:310 failed to connect to ipsec : 192.168.10.10[4501]
(T3900)Info ( 321): 07/23/20 09:03:15:310 Connecting to 192.168.10.10 failed
(T3900)Debug( 651): 07/23/20 09:03:15:310 Retry connect failed second time
(T3900)Debug( 550): 07/23/20 09:03:17:312 Network is reachable
(T3900)Debug( 166): 07/23/20 09:03:17:312 Trying to do ipsec connection to 192.168.10.10 [4501]
(T3900)Debug( 550): 07/23/20 09:03:17:314 Network is reachable
(T3900)Info ( 321): 07/23/20 09:03:23:317 Connecting to 192.168.10.10 failed
(T3900)Debug( 651): 07/23/20 09:03:23:317 Retry connect failed third time
(T3900)Debug( 769): 07/23/20 09:03:23:317 Tunnel retry done: failed retry
(T3900)Debug(6450): 07/23/20 09:03:23:318 --Set state to Disconnecting...

 


Environment


  • Windows 10, Windows 10X 
  • GlobalProtect
  • Modern standby feature. 


Cause


  • Modern Standby starts when the user causes the system to enter sleep (e.g user pressing the power button, closing the lid, idling out, or selecting Sleep from the power button in the Windows Start menu).
  • Windows pauses all desktop applications and throttles the runtime of third-party system services during modern standby. 


In order to confirm that a machine has modern standby as a sleep state, run the following command in a command prompt:
 
C:\Users\Alias> powercfg/a
    The following sleep states are available on this system:
    Standby (S0 Low Power Idle) Network Connected <<<---- This output indicates that Modern standby is supported on this device
    Hibernate
    Fast Startup


 


Resolution


GlobalProtect supports modern standby starting from version 5.1.7+ and 5.2.4+. In order to avoid unexpected disconnects related to modern standby, it is recommended to upgrade to 5.1.8 or 5.2.7+. The addressed issues below are related to the modern standby feature.

  •  GPC-11638
  •  GPC-12356 
  •  GPC-12266

Reference:
 Addressed Issues in GlobalProtect App 5.1
 Addressed issues in GlobalProtect App 5.2



Additional Information


  • GlobalProtect can detect when the machine goes into and comes out from modern standby. 
  • If the VPN connection is interrupted before the machine enters modern standby, GlobalProtect does not try to restore the VPN connection.
  • Once the machine wakes up from modern standby, GlobalProtect will resume with the tunnel restoration.
  • If restoring the tunnel - for some reason - fails, then:
  1. GlobalProtect will do a network discovery (Always-On connect method).
  2. GlobalProtect will disconnect (On-demand connect method).

For more details regarding Windows modern standby, please refer to:
Modern Standby Key Concepts


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LjpCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language