GlobalProtect隧道与现代备用计算机不一致

GlobalProtect隧道与现代备用计算机不一致

9719
Created On 09/23/21 00:27 AM - Last Modified 07/18/25 20:36 PM


Symptom


  • 计算机进入现代待机状态
(P4168-T4172)Info ( 397): 08/05/21 17:34:11:734 Received powersetting change event
(P4168-T4172)Debug(15149): 08/05/21 17:34:11:734 Modern standby
  • GlobalProtect 尝试恢复隧道,但是数据包发送失败。隧道瘫痪。
Debug(6932): 08/05/21 17:34:20:645 --Set state to Restoring VPN Connection
08/05/2021 17:34:20:645 [Info ]: Tunnel is down due to packet sending failure.
08/05/2021 17:34:20:645 [Info ]: Gateway UMD Gateway : Checking network availability and restoring VPN connection when network is available.
  • 从现代待机中唤醒。由于现有隧道无法持久,这就是隧道断裂和用户断开隧道连接的原因
P4168-T4172)Debug(15158): 08/05/21 18:38:03:496 Wakeup from modern standby
(P4168-T7600)Debug(15231): 08/05/21 18:38:03:496 Waked up from modern standby
(P4168-T7600)Debug( 758): 08/05/21 18:38:03:496 Tunnel downtime (3830969 milliseconds) exceeds retry grace period (1800 seconds)
(P4168-T7600)Debug( 901): 08/05/21 18:38:03:496 Tunnel retry done: failed retry
(P4168-T7600)Info ( 916): 08/05/21 18:38:03:496 Before ProcMonitor quit, disconnect vpn
(P4168-T7600)Debug(10816): 08/05/21 18:38:03:496 m_preUsername azi
(P4168-T7600)Debug(1441): 08/05/21 18:38:03:496 m_msp->IsVPNConnected() is 0, CControlManager::GetInstance()->IsInRetry() is 0
(P4168-T7600)Debug(6932): 08/05/21 18:38:03:498 --Set state to Disconnecting...
  • 从现代待机状态唤醒后,如果隧道可以持久(VPN恢复),GlobalProtect 不会重新创建隧道。
  • 但是,有时VPN 隧道未恢复,则现有隧道无法持久。在这种情况下,物理网络在现​​代待机期间可能不可用(无法 ping 通)。隧道关闭时间超过了配置的宽限期。因此,隧道中断是意料之中的事。


Environment


  • PAN OS 9.1
  • GlobalProtect 5.2,6.1,6.2
  • 现代待机 Windows 设备。


Resolution


1-将设备的屏幕锁定器更改为具有更长屏幕锁定时间(例如锁定屏幕两个小时或更长时间)

2-刷新gp 连接并手动登录gp



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMX7CAM&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language