Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.
To work around this problem, you must increase the time-out value for IPSec Security Association Idle Timer. To do this, follow these steps:
- Click Start, click Run, type regedit, and then click OK.
- Locate and then click the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPsec
- Add the SAIdleTime registry entry. If this entry already exists, modify the value. To do this, follow these steps:
- Right-click the
IPSec
registry key, click New, and then click DWORD Value. - Type SAIdleTime, and then press ENTER.
- Right-click the SAIdleTime registry entry, and then click Modify.
- Click Decimal, type 3600 in the Value data box, and then click OK.
Note The default value for the SAIdleTime
registry entry is 300 seconds. The maximum value that you can set for the entry is 3,600 seconds. You must set the value to 3,600.
- Exit Registry Editor.
- Restart the computer.
Note You must set the same
SAIdleTime
registry entry value on each side of the IPsec tunnel if the remote VPN Tunnel endpoint is a Windows-based server. If the remote tunnel endpoint is not a Windows-based VPN server, see the product documentation on how to change the IPSec Security Association Idle Timeout value.