SecuExtender Agent: VPN drops when user attempts to login with RDP
As the title states above, the VPN drops when the user launches RDP and attempts to login remotely. User's home workstation is Windows 10.
This part of the log file stands out, but I don't know what to make of it:
Edit: Some pertinent details...
This part of the log file stands out, but I don't know what to make of it:
[ 2023/02/13 19:30:03 ][SecuExtender Agent][INFO] security tunnel is created! [ 2023/02/13 19:30:03 ][SecuExtender Agent][DEBUG] Entering main loop [ 2023/02/13 19:30:03 ][SecuExtender Agent][INFO] GetOverlappedResult success, agentState.aState = 2, agentState.aError = 0, dwReadBytes = 8 [ 2023/02/13 19:30:03 ][SecuExtender Agent][INFO] GetOverlappedResult success, agentState.aState = 3, agentState.aError = 0, dwReadBytes = 8 [ 2023/02/13 19:30:48 ][SecuExtender Agent][WARN] The device is going to close the connection. [ 2023/02/13 19:30:48 ][SecuExtender Agent][ERROR] Failed to recv from SSL socket :-66 (0x0) [ 2023/02/13 19:30:48 ][SecuExtender Agent][DEBUG] SSL Connection is going to be closed
Edit: Some pertinent details...
- ATP800 running firmware version 5.32.
- SecuExtender version 4.0.4.0.
- User's home workstation is running Windows 10.
- Remote workstation being connected to is running Windows 11.
0
Accepted Solution
-
Hi @RSaull
Please refer to this FAQ article SSL VPN disconnect due to invalid packet size to fix your problem. Please check if the MTU size of "TAP-Windows Adapter V9 for Zyxel SecuExtender " of Network adapter is 1370 in your PC.
Thanks .
See how you've made an impact in Zyxel Community this year!
1
All Replies
-
Sorry for not having a solution or knowing the cause, but I would hazard a guess at incompatibility between the VPN target (office) and the version of RDP running on Windows 10. (MS Remote Desktop?) Could the office device be in need of a firmware upgrade? Which model is the office device?0
-
Hi @RSaull
As smb_corp_user mentioned that what is your device and its firmware? What is your SecuExtender software version? While VPN is dropped, are there any dropped messages that can be watched on the Monitor log page? Thanks.See how you've made an impact in Zyxel Community this year!
0 -
Zyxel_Jeff said:Hi @RSaull
As smb_corp_user mentioned that what is your device and its firmware? What is your SecuExtender software version? While VPN is dropped, are there any dropped messages that can be watched on the Monitor log page? Thanks.
ATP800 running firmware version 5.32.
SecuExtender version 4.0.4.0.
User's home workstation is running Windows 10.
Remote workstation being connected to is running Windows 11.0 -
try firmware 5.350
-
Hi @RSaull
Thanks for your update. While the SSL VPN is dropping can you see any blocked or drop messages on the Monitor > Log > View Log ? Not sure if it dropped by "match the default rule" or security services? It belongs to "match the default rule drop", please add a security policy to allow the traffic which is from SSL VPN to LAN direction. If it is dropped by the security service, please disable the service. Thanks .See how you've made an impact in Zyxel Community this year!
0 -
@Zyxel_Jeff,
From the monitor log:SSL tunnel receives a packet with invalid packet size SSL tunnel has been disconnected
We have several users who routinely use the VPN & Remote Desktop without issues. The security policies are correctly configured.
0 -
Is MTU before going VPN 1500?
Do you use PPP for WAN?1 -
Hi @RSaull
Please refer to this FAQ article SSL VPN disconnect due to invalid packet size to fix your problem. Please check if the MTU size of "TAP-Windows Adapter V9 for Zyxel SecuExtender " of Network adapter is 1370 in your PC.
Thanks .
See how you've made an impact in Zyxel Community this year!
1 -
Zyxel_Jeff said:Hi @RSaull
Please refer to this FAQ article SSL VPN disconnect due to invalid packet size to fix your problem. Please check if the MTU size of "TAP-Windows Adapter V9 for Zyxel SecuExtender " of Network adapter is 1370 in your PC.
Thanks .
A question remains . . . We have 50 +/- users who use remote desktop over the VPN with no problems. One would assume that the MTU size of their network adapters are the default value. We don't recall ever changing the MTU sizes. Why would we only see issues with this one user?0 -
By default its 1370 so someone changed it...1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.8K Security
- 284 USG FLEX H Series
- 278 Security Ideas
- 1.5K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 251 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight