cancel
Showing results for 
Search instead for 
Did you mean: 

Three 5G internet blocks Pulse SEcure (ivanti) VPN disconnects

Three5GVPN
Regular

I saw some other posts of this topic with NO solution, and yes, another Three 5G user suffering the same problem with VPN, with Pulse Secure.

Let me explain:

I got a really good 5G signal, no issues, but when connected to the VPN Pulse Secure (required for work) the connection drops every 3 minutes. Yes, exactly 180 seconds. That makes work remotely impossible...

Company IT team has been looking into it unsuccessfully.  Finally we tested the same Laptop and the same VPN Pulse secure doing hotspot from another 5G internet provider and it worked fine. 

So the problem is only with Three 5G.

I have also contacted with Pulse Secure support team. They have investigated and concluded that is the Internet provider blocking the connection every 3 minutes. 

 

All this makes me feel switching provider...

 

I found this link, more people having very similar cases.:

 

https://community.pulsesecure.net/t5/Pulse-Connect-Secure/Connecting-via-hotspot-or-5G-modem-Three-Z...

 

I got external technical support guy suggesting me that there is nothing to do on the router Setup, since this is the Provider (Three) network affecting negatively to the VPN.  I have tried the 5G broadband sim card in a  phone and same issue.  But on the same phone, doing hotspot with another sim card then it works perfectly. The issue is only with Three network.  Already done so many checks that this is a fact: Three UK is blocking Pulse Secure VPN.  this makes impossible to work from home. Therefore Three 5G broadband useless and unless there is a solution I will need to switch provider.

54 REPLIES 54
NP1205
Fledgling

@JonathanB Hello,

I am currently experiencing issues and would like to try and help as my last resort would be to find a new provider.

Markensite
Fledgling

Hi All,

I have a 'work around' for this problem that works for me - perhaps it will help you...

Long story short: try somehow disrupting the port that PulseSecure/Ivanti is using - in my case it is port 4500, and I disrupted it in my router settings.  This forced the connection to fall back to more stable protocol - it's not perfect, but does lead to connections that generally last up to 8 hours.

For the more complete story, keep reading, but please note that I am not a computer/network expert so don't flame me if I get anything technical wrong - the stuff below is just what I've been forced to learn over the last six months whilst trying to solve my connection problems!

_________________________________

Background:  I have had exactly the issues as described by the original poster @Three5GVPN - I am using my company laptop which uses Ivanti (previously Pulse Secure) and I use a 4G router with a Three SIM.  I was losing connection every three minutes (e.g. if using SAP, or remotely controlling another computer, or connected to a database, I would momentarily lose connection every three minutes and would have to log back on again - basically it was not possible to do my work!).

When I say three minutes, I mean almost exactly three minutes, predictable to within a second or two.

I also found that:

- I had the same issue when using my phone's hotspot (using a Smarty SIM - Smarty also use the Three network)

- I had no issues when I used a Lebara SIM - Lebara use the Vodafone network.

Additionally: I found that I did occasionally get a good stable connection which lasted much longer than three minutes - from a few minutes to eight hours long (remember that - it's important for the story...)

When did my problems start?  In the past, I was able to use Pulse Secure just fine *(see asterisk later).  My problems started when the company IT dept updated Pulse Secure to a newer version, and later on, updated to Ivanti.  So you see, the problem seems to be a combination of  i) the Three network and ii) the update of the Pulse Secure/Ivanti software (or maybe a change in the PulseSecure/Ivanti settings).

Investigations: My company IT dept was unable to get anywhere, so after a few months, I decided to look into it myself.  I trawled through the event logs that you can generate: From the Ivanti app, select File, Logs, Log Level, Detailed, then select File, Logs, Save As and save to your computer.

From the logs, I saw that the VPN usually uses a protocol called ESP - it is these ESP connections that disconnect every three minutes.  However, when I investigated the occasional stable connections, I saw that these occurred when there were reports of 'missing heartbeats', presumably due to a poor mobile signal - these caused the VPN to switch from ESP to an alternative protocol called SSL.

These SSL connections are more stable - though perhaps a bit laggy - they can last just a few minutes but more often than not, over an hour.  See example below, where I had a good, eight hour connection from 08:04:58 to 16:07:18 after the connection switched from ESP to SSL due to missing heartbeats:

Markensite_0-1696247756104.png

(so ironically, it seems that maybe a poor mobile signal leads to a good connection!)

You can see what sort of connection you have without needing to save any logs.  From the Ivanti app, select File, Connections, Advanced Connection Details... see examples of SSL and ESP connections below:

Markensite_1-1696247793682.pngMarkensite_2-1696247804947.png

So, I wondered if there was a way to force the system to use an SSL connection... this is what I found:

How to kill the ESP connection, and get a stable SSL connection: During discussions with my IT dept, I found out that the ESP connection uses 'udp Port 4500',  ( I contacted Three Technical Support to ask about this - they told me that there were no restrictions on port 4500...) so my plan was to try to disrupt port 4500 to force the VPN from ESP mode into SSL mode... I found a way to do this using my router settings:

Router: Huawei B593s-22

I found a security setting 'ALG' and told it to use port 4500, and then enabled it - see below:

Markensite_3-1696247839426.png

Success! After changing the settings and restarting the router,  my ESP connection always gets these 'missed heartbeats' and reverts to SSL mode after about 20 seconds.  So now, using SSL mode, I am able to do my work.  However, I don't think this is a fix, it's just a work around until someone figures out what the real issue is - my connections are now good enough for me to do my work, but they do seem a bit laggy and they do sometimes still disconnect after only a few minutes.

Another Option? If you can't configure your router like I did then, if you have admin rights on your PC, I think you can block Port 4500 in the computer settings - that might also work - I don't know for sure as I haven't tried it, but it's worth a shot...

(*Actually from the event logs it looks like, in the period before my problems started, before the original PulseSecure update, the connection was also disconnecting every three minutes - however, it did not cause me any noticable issues... I can't explain that, but there's a clue there somewhere... maybe something changed in Pulse Secure regarding how it handles momentary disconnections? - I do have some suspicions about a 'dynamic trust' configuration setting, but haven't really investigated it yet...)

NP1205
Fledgling

Hello, Appreciate this post a lot. I have the exact same issue. My specific router is the ZTE MC888 and the VPN I am trying to use is PULSE Secure. 

Unfortunately, the network configuration page does not allow me to specify an SIP ALG port and just has 2 radio buttons (Enable and Disable). 

I tried to block the port in my PCs firewall settings but this caused PULSE to not connect at all. My last resort is currently speaking to my IT Department and seeing if they know of a way to force the VPN type to SSL. OR cancel my contact with 3 and find a provider which doesn't cause this issue.

JonathanB
Community Moderator
Community Moderator

Hi @Markensite,

Thanks for sharing this, I'll flag it up to the investigating team in case it helps them.

Jonathan



Mod tip! The author of a post can hit 'Accept as Solution', to highlight a reply that helped solved their query.


Avondale
Rising star

@JonathanB 

Do you have the power to "pin" a VPN thread at the top of the Three Community page ? 

I can see lots of advantages in everyone having easy access to the same VPN thread, rather than having the problems - and the solutions - scattered over lots of different threads at different times.  

Avondale
Rising star

@Markensite 

I am not a user of that VPN so those instructions don't apply to me. But I have bookmarked your post for the future, as I suspect that your words could be useful as a point of reference for other users of that VPN. Thanks !  

SJ
Fledgling

We have also had problems connecting to Pulse Secure VPN.  We are using The Three UK network with the APN '3internet'.  We try to connect to a large multinational company which uses both a Pulse Secure Connection for the USA and an additional Pulse Secure Connection for the UK.  What is interesting is that we can connect to the USA Pulse Secure Connection, but we CANNOT connect to the Pulse Secure Connection for the UK.  I think this adds weight to the conclusions others have drawn from their own experiences - it is nothing to do with router set up.  There is clearly an incompatibility between Three UK and the connections available from Pulse Secure in the UK.  We would appreciate a fix ASAP!

Avondale
Rising star

@SJ 

Have you found and unsuccessfully tried the other fix detailed on this forum ? 

vcanil
Fledgling

Is the issue fixed or still remains??

Avondale
Rising star

@vcanil 

As far as I am aware, VPNs are still an issue with Three 5G Broadband. 

I had hoped that @JonathanB might review and comment on this thread, but he does not yet seem to have done so.