This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN - Remote Access

Hi, I am using a XG115 (SFOS 17.5.5 MR-5). I have created few SSL VPN connection for user in Malaysia (Local), Hong Kong, and China. We have no problem connecting from Malaysia and Hong Kong, but all user from China fail to connect. The following are the log for your reference:

Mon Aug 19 11:33:34 2019 OpenVPN 2.3.8 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Jul 3 2017
Mon Aug 19 11:33:34 2019 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.09
Enter Management Password:
Mon Aug 19 11:33:34 2019 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Aug 19 11:33:34 2019 Need hold release from management interface, waiting...
Mon Aug 19 11:33:35 2019 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Aug 19 11:33:35 2019 MANAGEMENT: CMD 'state on'
Mon Aug 19 11:33:35 2019 MANAGEMENT: CMD 'log all on'
Mon Aug 19 11:33:35 2019 MANAGEMENT: CMD 'hold off'
Mon Aug 19 11:33:35 2019 MANAGEMENT: CMD 'hold release'
Mon Aug 19 11:33:42 2019 MANAGEMENT: CMD 'username "Auth" "leoli"'
Mon Aug 19 11:33:42 2019 MANAGEMENT: CMD 'password [...]'
Mon Aug 19 11:33:42 2019 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Aug 19 11:33:42 2019 Attempting to establish TCP connection with [AF_INET]175.145.235.177:8443 [nonblock]
Mon Aug 19 11:33:42 2019 MANAGEMENT: >STATE:1566185622,TCP_CONNECT,,,,,,
Mon Aug 19 11:33:43 2019 TCP connection established with [AF_INET]175.145.235.177:8443
Mon Aug 19 11:33:43 2019 TCPv4_CLIENT link local: [undef]
Mon Aug 19 11:33:43 2019 TCPv4_CLIENT link remote: [AF_INET]175.145.235.177:8443
Mon Aug 19 11:33:43 2019 MANAGEMENT: >STATE:1566185623,WAIT,,,,,,
Mon Aug 19 11:33:43 2019 Connection reset, restarting [-1]
Mon Aug 19 11:33:43 2019 SIGUSR1[soft,connection-reset] received, process restarting
Mon Aug 19 11:33:43 2019 MANAGEMENT: >STATE:1566185623,RECONNECTING,connection-reset,,,,,
Mon Aug 19 11:33:43 2019 Restart pause, 5 second(s)
Mon Aug 19 11:33:48 2019 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Aug 19 11:33:48 2019 Attempting to establish TCP connection with [AF_INET]192.168.0.130:8443 [nonblock]
Mon Aug 19 11:33:48 2019 MANAGEMENT: >STATE:1566185628,TCP_CONNECT,,,,,,
Mon Aug 19 11:33:58 2019 TCP: connect to [AF_INET]192.168.0.130:8443 failed, will try again in 5 seconds: ϵͳÊÔͼ½«Çý¶¯Æ÷ºÏ²¢µ½ºÏ²¢Çý¶¯Æ÷ÉϵÄĿ¼¡£
Mon Aug 19 11:33:58 2019 SIGUSR1[soft,init_instance] received, process restarting
Mon Aug 19 11:33:58 2019 MANAGEMENT: >STATE:1566185638,RECONNECTING,init_instance,,,,,
Mon Aug 19 11:33:58 2019 Restart pause, 5 second(s)
Mon Aug 19 11:34:03 2019 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Aug 19 11:34:03 2019 Attempting to establish TCP connection with [AF_INET]192.168.0.1:8443 [nonblock]
Mon Aug 19 11:34:03 2019 MANAGEMENT: >STATE:1566185643,TCP_CONNECT,,,,,,

What caused the connection fail? China Firewall?

What is the alternative solution if I want China users to connect to the SSL VPN? 

Thank you.



This thread was automatically locked due to age.
Parents
  • Hi  

    The logs shown below mentions that connection was indeed establised but then it was reset.

    Wee Yap Tan said:
    Mon Aug 19 11:33:42 2019 Attempting to establish TCP connection with [AF_INET]175.145.235.177:8443 [nonblock]
    Mon Aug 19 11:33:42 2019 MANAGEMENT: >STATE:1566185622,TCP_CONNECT,,,,,,
    Mon Aug 19 11:33:43 2019 TCP connection established with [AF_INET]175.145.235.177:8443
    Mon Aug 19 11:33:43 2019 TCPv4_CLIENT link local: [undef]
    Mon Aug 19 11:33:43 2019 TCPv4_CLIENT link remote: [AF_INET]175.145.235.177:8443
    Mon Aug 19 11:33:43 2019 MANAGEMENT: >STATE:1566185623,WAIT,,,,,,
    Mon Aug 19 11:33:43 2019 Connection reset, restarting [-1]
    Mon Aug 19 11:33:43 2019 SIGUSR1[soft,connection-reset] received, process restarting
    Mon Aug 19 11:33:43 2019 MANAGEMENT: >STATE:1566185623,RECONNECTING,connection-reset,,,,,
    Mon Aug 19 11:33:43 2019 Restart pause, 5 second(s)
    Mon Aug 19 11:33:48 2019 Socket Buffers: R=[65536->65536] S=[65536->65536]

    It would be better if you check the SSL VPN logs from XG as well and see what was causing the connection reset.

    Further, You may try to use Sophos Connect Client VPN which based on IPSec and might help you in this situation.

  • Hi Jaydeep,

    I am trying to search for IPSec Remote Access VPN configuration step, but can't find any in the Community Portal. Could you please guide me on the configuration step-by-step?

    Thank you. 

Reply Children
No Data