IPSec VPN Session Reauthentication Issues and Workaround
Options
Zyxel_Kevin
Posts: 975
Zyxel Employee
Zyxel Employee
in VPN
Question:
How to manage IPSec VPN session reauthentication when the GUI setting isn't working, and what is the permanent solution?
Answer:
The reauthentication/lease time setting for IPSec VPN sessions may not function as expected through the User Interface (GUI), leading to sessions remaining active beyond their configured duration. This is due to a known software bug.
- Root Cause: The
reauth/lease timesetting within the Userfield in the GUI was incorrectly applied to IPSec users; it was originally designed for Web Authentication only. This has been identified as a bug that will be addressed in a future firmware release. - Resolution:
- Immediate Workaround (CLI Configuration):
To enforce reauthentication for IPSec VPN users immediately, you can use the Command Line Interface (CLI) via SSH.- Steps:
- Log in via SSH to your device.
- Enter configuration mode:
edit running - Set the reauthentication time (e.g., 8 hours):
vrf main ike ike-policy-template RemoteAccessike-t reauth-time 8h - Commit the changes:
commit - To ensure the setting persists across reboots, save the running configuration to startup:
copy running startup
- Important Notes:
- This CLI command applies the reauthentication time to all VPN users.
- Manually changing this setting via SSH will not cause issues with the WebGUI, and subsequent changes in the WebGUI will not undo this manual setting.
- Steps:
- Permanent Fix (Firmware Update):
A permanent fix for this issue, allowing proper reauthentication configuration via the GUI for IPSec VPN users, is expected in the next firmware release (FCS), estimated for October. Users should monitor for this release.
- Immediate Workaround (CLI Configuration):
0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 208 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 529 USG FLEX H Series
- 333 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 292 Service & License
- 461 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight