Hi,
Our system: NW 6.5 sp3, bm 3.8 sp3, VPNClient 3.8.9, NCF 2.0.

Our Client-to-Site service is set up to "Keep Alive Automaticaly"
and even so clients get thrown off.
The Novell Client and VPN client is set to use NMAS.
(In older days it was set up to use "Backward Compatibility" but then the
users throw each other off, when having same private ipadress.)
Below here is some lines from our log. Look at 10/31/2005 10:37:18 AM

Do You have an idea?

Regards

Christian

10/31/2005 10:37:30 AM IKE ESP-SA is deleted mySPI=C3523B96
peerSPI=4897F7E3 dst :80.196.222.78
10/31/2005 10:37:30 AM IKE ESP-SA is deleted mySPI=6DE07336
peerSPI=44D0B1D2 dst :80.196.222.78
10/31/2005 10:37:30 AM IKE Ipsec deleted ESP-SA mySPI=C3523B96
peerSPI=4897F7E3 dst :80.196.222.78
10/31/2005 10:37:30 AM IKE Ipsec deleted ESP-SA mySPI=B5E1B79D
peerSPI=00A5B3B3 dst :80.196.222.78
10/31/2005 10:37:28 AM IKE Ipsec deleted ESP-SA mySPI=6DE07336
peerSPI=44D0B1D2 dst :80.196.222.78
10/31/2005 10:37:28 AM VPN Control Client CN=XXXX.OU=AAAA.OU=BBBB.O=CC
removed from IPSEC.
10/31/2005 10:37:18 AM IPSec Packet discarded during policy checking,
src=195.249.206.2, dst=1.0.0.17
10/31/2005 10:37:18 AM VPN Control A timeout disconnect has occurred
for client CN=RGD.OU=PROD.OU=Virum.O=BK.
10/31/2005 10:36:08 AM IKE ESP SA was created successfully with
194.19.148.196
10/31/2005 10:36:08 AM IKE Received proxy id ID_IPV4_ADDR 1.0.0.18
10/31/2005 10:36:08 AM IKE Received proxy Id : IPV4 SUBNET
172.16.0.0/255.255.0.0
10/31/2005 10:36:08 AM IKE IPSEC SA NEGOTIATION - Peer lifetime is:
7200 My lifetime is: 7200
10/31/2005 10:36:08 AM IKE Sending proxy id: Type 1 1.0.0.18
10/31/2005 10:36:08 AM IKE Sending proxy id :Type 4
172.16.0.0/255.255.0.0
10/31/2005 10:36:08 AM VPN Tunnel Received an IP call from
CN=YYYY.OU=AAAA.OU=BBBB.O=CC @ 1.0.0.18
10/31/2005 10:35:54 AM IKE ESP SA was created successfully with
194.19.148.196