Windows 10: IPsec SA timeout blocks new session

Discus and support IPsec SA timeout blocks new session in AntiVirus, Firewalls and System Security to solve the problem; Environment:- Win 10 client, connected to Srv 2016 DC- IPsec enabled as basic "Connection Security Rule" through GPO with default settings- Environment... Discussion in 'AntiVirus, Firewalls and System Security' started by CalleM, Apr 27, 2021.

  1. CalleM Win User

    IPsec SA timeout blocks new session


    Environment:- Win 10 client, connected to Srv 2016 DC- IPsec enabled as basic "Connection Security Rule" through GPO with default settings- Environment has more than basic hardening, based on CIS- No network security measures Dot1x, NIDS etc are in placeProblem flow chart:1 - At client start up, IPsec transport mode is initiated with no issues and user can log on2 - When client reboots, Main mode SA is terminated but quick mode SA stays active on server3 - When user tries to logon they get errors, boiling down to that IPsec connection is not established4 - After 5 minuter timeout netsh ad

    :)
     
    CalleM, Apr 27, 2021
    #1

  2. IPSec issues. (Microsoft Domain Isolation)

    We have Microsoft Domain Isolation set-up on our network. Lately, my computer doesn't allow new inbound IPSec protected connections from other computers, however it will allow them outbound.

    For example:

    My computer and the other computer are part of the same domain and use the same group policy and firewall settings.

    Other computer IPSec connection to My computer - no connection

    My computer to other computer - IPSec connection is established.

    Once IPSec connection is established

    Other computer connection to My computer - connection is established until my computer gets restarted.

    Unportected (by IPSec) inbound connections, get established without issues.

    The rest of the computers in the network do not exibit these issues.

    I tried the following troubleshooting steps:

    I cleared SA by using:

    netsh ipsec dynamic delete sa (or delete all)

    Full reset of the Windows Firewall.

    Unjoin-rejoin my computer to the domain.

    None of the steps have worked.

    Thank you.
     
    Alexandru_Lapugean, Apr 27, 2021
    #2
  3. msworkg Win User
    Windows IPsec Ikev2 client Rekeying default timeout

    Hi!

    Help me please!

    Please tell me, is there a certain timeout for the connection of the IPsec client in Windows?
    I have already set all the possible parameters on the server and everything has been tried, everything is turned off, the key exchange is turned off, the IPsec tunnel lifetime has been increased - but it's all useless - according to the server’s logs,
    it seems that Windows itself initiates the tunnel break after 7:45 + - hours

    here, by reference, someone wrote that there is some kind of default timeout IKE_SA
    IPsec/IKEv2 VPN: Tips when connecting a Windows 7, Windows 8 or Windows 10 VPN Client with Rockhopper.

    a question for connoisseurs, is this really so? I can’t find this information anywhere
    The versions of Windows 10 are different, from 1607 LTSB, 1903, - on all versions of IPsec ikev2 breaks the same way after about 7:45 hours ..

    user authentication is carried out through the AD RADIUS server on Windows server 2008 (not R2).
    IPsec server - strongswan 5.8.2 at pfsense
     
    msworkg, Apr 27, 2021
    #3
  4. IPsec SA timeout blocks new session

    How do I open up a new session in IE10?

    Hi David,

    Here are the steps on how to open a new session in Internet Explorer:

    • Search Internet Explorer.
    • Click Alt.
    • Go to File.
    • Then click New session.

    Note: This option is only available in Internet Explorer 11.

    Let us know how that turned out for you.
     
    Marilou Ser, Apr 27, 2021
    #4
Thema:

IPsec SA timeout blocks new session

Loading...
  1. IPsec SA timeout blocks new session - Similar Threads - IPsec timeout blocks

  2. Session timeout for internet by windows 11

    in Windows 10 Software and Apps
    Session timeout for internet by windows 11: When connecting to my college internet via LAN, I encounter a situation where I need to repeatedly log in with my credentials after a few minutes. I would like to understand why this is happening and find a solution to prevent this frequent timeout....
  3. Session timeout for internet by windows 11

    in Windows 10 Gaming
    Session timeout for internet by windows 11: When connecting to my college internet via LAN, I encounter a situation where I need to repeatedly log in with my credentials after a few minutes. I would like to understand why this is happening and find a solution to prevent this frequent timeout....
  4. RDP Windows 11, Session blocked by: Local Session Manager

    in Windows 10 Gaming
    RDP Windows 11, Session blocked by: Local Session Manager: I recently updated my work computer to Windows 11 about bought a new laptop that also uses Windows 11. When I work from home I used Remote Desktop Connection to log into my work computer. I'm fine for a decent number of hours but then suddenly I get bumped from the work...
  5. RDP Windows 11, Session blocked by: Local Session Manager

    in Windows 10 Software and Apps
    RDP Windows 11, Session blocked by: Local Session Manager: I recently updated my work computer to Windows 11 about bought a new laptop that also uses Windows 11. When I work from home I used Remote Desktop Connection to log into my work computer. I'm fine for a decent number of hours but then suddenly I get bumped from the work...
  6. LT2P/IPsec VPN

    in Windows 10 Gaming
    LT2P/IPsec VPN: I want to use LT2P/IPsec to connect a Windows 10 client over the internet to a Windows 2019 server. After connecting, the client should still be able to browse the internet. The client needs access to the server's disks Drive mappings and to a service running on a port.So...
  7. LT2P/IPsec VPN

    in Windows 10 Software and Apps
    LT2P/IPsec VPN: I want to use LT2P/IPsec to connect a Windows 10 client over the internet to a Windows 2019 server. After connecting, the client should still be able to browse the internet. The client needs access to the server's disks Drive mappings and to a service running on a port.So...
  8. LT2P/IPsec VPN

    in Windows 10 Network and Sharing
    LT2P/IPsec VPN: I want to use LT2P/IPsec to connect a Windows 10 client over the internet to a Windows 2019 server. After connecting, the client should still be able to browse the internet. The client needs access to the server's disks Drive mappings and to a service running on a port.So...
  9. Fix Forza Horizon 4 IPsec Error – Unable to join session

    in Windows 10 News
    Fix Forza Horizon 4 IPsec Error – Unable to join session: [IMG]Gamers who play Forza Horizon 4 quite often may one day come across errors known as IPsec errors. The accompanying error codes could be 0x8923203f, 0x89232000, 0x80600208, 0x801901F4, or 0x89232001. We understand that only folks who play the game on Windows 11/10 and...
  10. Windows IPsec Ikev2 client Rekeying default timeout

    in Windows 10 Network and Sharing
    Windows IPsec Ikev2 client Rekeying default timeout: Hi! Help me please! Please tell me, is there a certain timeout for the connection of the IPsec client in Windows? I have already set all the possible parameters on the server and everything has been tried, everything is turned off, the key exchange is turned off, the IPsec...