Hi Pham,
What kind of times are you talking about with regards to "idle for a period of time"?
Minutes?
Hours?
Offline for a few days?
Does it show itself when the client is connected with all types of tunnels? (IPHTTPS, Teredo, 6to4)
Is the client able to reestablish the connection again after a few minutes or do you need to reboot it (or even move it into corporate lan) to regain the functionality?
A good place to start is to generate a logfile from DCA on a client that has lost it's connectivity and post parts from it here (a good start is the the status regarding the various interfaces and if the NRPT effective policy is empty or not)
Best wishes,
Jonas Blom