Open eitzenbe opened 3 years ago
after some time
How long is "some time"? Does it match the rekey and/or HIP report intervals sent by the server, and shown in OpenConnect's logging output? (That'd be my guess :point_down:)
…the vpn tunnel routes stall after the following message is shown on console:
I don't believe this has anything to do with vpn-slice
(the "normal" vpnc-script does similarly little upon reason=reconnect
), but if you can demonstrate otherwise then please explain.
Need more info to be sure (openconnect -vvvv --dump
; ip route
before-and-after), but one guess is that the server doesn't like something about the HIP report (re)check and is blocking your connectivity after that point.
I'm not clear what's causing the reconnect, but perhaps a re-key on the same interval as the HIP check.
Please build the latest-and-greatest OpenConnect from source, since it improves the logging for GlobalProtect among other things, and file an issue with more details upstream at https://gitlab.com/openconnect/openconnect/issues.
When using openconnect against GPA VPN Gateway with split vpn, after some time the vpn tunnel routes stall after the following message is shown on console: