Always on VPN, occasionally "New policy invalidated SAs formed with old policy"

A.B.J 21 Reputation points
2022-04-11T11:36:38.14+00:00

The short summary:

AoVPN works great in general. It's about 2k users. We use IKEv2 with both DT and UT-tunnel. We use F5 for LB and SRV2019.

Occasionally, I hear from a handful of users "I needed to reconnect a few times before it worked..". I assume it correlates to too large UDP packets and the client might already been authenticated through NPS and the persistance routes behind NAT-T is already established, hence it needs to timeout before the user could try again?
When I think about it, it sounds more like an issue with the DT-Tunnel rather than UT, since DT connects before the user logs on.

I have not traced the traffic yet for these particular events since it's pretty hard because you don't know when it will happen.
I might need to setup a 24/7 wireshark to catch any of these events but was wondering if someone found any details that I've might have missed?

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
551 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,381 Reputation points
    2022-04-12T08:15:03.623+00:00

    Hello ABJ,

    Before starting with the network traces, I can recommend you check logs during the time of connection failed, in order to retrieve more information why the connection could not be established.

    You have the reference for the files involved here:
    https://learn.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-troubleshooting#logs

    ---------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.