Skip to main content

I have a subset of users on Mac device that are telling me that meetings (Google Meet, Slack Huddle etc.) are very choppy. I have added google.meet.com and Slack URLS to the steering domain bypass. But still having issues, I see in alot of these users logs:

Tunnel down due to error
Detected Dead Peer

The below is seen the most:

Tunnel down due to error
Tunnel Down Due to SSL Error

 

I have had users disable IPv6, power cycle their home modem and router, some have contacted their ISP and click renew DCHP many times. 

Any thoughts?

I have had a few Mac users complaining about similar issues and also see the Tunnel Down Due to SSL Error.  I plan to open a ticket with support

 


I have had a few Mac users complaining about similar issues and also see the Tunnel Down Due to SSL Error.  I plan to open a ticket with support

 

I have spoken with them and they are not giving really any good answers. I am having to disable Netskope for some of my users. Let me know what happens when you contact them Thanks

 


@bcatten what did Netskope support say for you on this issue?

They are stating it is my VPN or AV. but I just had a user have issues with google products while not on my VPN. I dont think it is my AV as if it was my entire company would have issues.


@drftordie Yeah, so far same for me.  They want me to disable AV and remove the VPN program, which I haven’t gotten to yet.  I also have 300 or so Mac’s not having issues that are all running the same AV and have the same VPN tool installed.  

 

You mentioned Google products which we don’t use, but I did see this article...not sure if your users are using firefox?  

Firefox browser stuck loading when using Google Services when the Netskope Client is enabled


If these are mac users, please try disabling IPv6. Turn it to Link-Local Only and then have the user reboot the Mac.


@zthompsoncr 
What my users have already done

  • Set IPv6 to Link-Local Only
  • Ensure their DNS IP’s are the ones from their ISP,
  • Power cycle their home router and or modem set power settings to :
  • Set the power settings to 
    • ‘Wake for network access’ - change to 'Never'
    • 'Prevent automatic sleeping on power adapter when the display is off' - ensure this is 'Enabled'

My users are having this issue with our VPN off/ not connected. I have made sure there is a certificate pinned app for my AV and ensured nothing on my AV is blocking Netskope. I have updated some users Netskope version from the “golden version” to the newest one as it was stated from Netskope support that they heard there where issue with the “golden version” and some of these users are still having issues. I just had a users to whom I uninstalled Netskope, re-installed it and was for some reason blocked from even logging into our VPN.

 

Any other suggestions?

@bcatten We still have issues in Firefox. Yeah this is a weird one forsure. I have tried looking at correlations in Mac processor, model, the applications on the device and have found no rhyme or reason. Also see above on what I have tried, maybe those steps will work for you
 


Do you have CFW or just NGSWG?


Do you have CFW or just NGSWG?

NGSWG


besides doing an IPv6 disable the next thing to look at is SSL Decryption but I typically don’t have to do that.. I typically have allowances for CFW (if you have it) but other than that I would have support look at it.


Hi ​@drftordie , Just wanted to check in to see if you get a chance to see ​@zthompsoncr response to your query.


Yeah, but I dont know what to look at when it comes to SSL Decryption. It looks correct to me. I have 3 Policies the one that came with my Netskope tenant ”Do Not Decrypt - Functionality Related” then one that does not decrypt specific users traffic like engineers etc.. and one that then does decrypt Engineers traffic but only for specific apps like Workday, Gemini and ChatGPT.


Hello ​@drftordie

 

Can you DM me the case number so I can look at the client logs?  Typically if you are seeing repeated slowness and disconnects we are going to want to determine if there is an underlying network issue along with a number of other items such as:
 

  • Are the users connecting to the appropriate data plane?  If not, why.
  • Is the client tunnel flapping causing reconnects? 

This is by no means exhaustive but these are some of the first items I typically check.  


@bcatten just wanted to see if you were able to get this solved?


Reply