This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OpenVPN Client Behind UTM

I'm having some challenges trying to identify the cause of my OpenVPN connection issues.

I am running OSx and Viscosity (app) to connect to an external (my works) OpenVPN Server via my Sophos UTM.  When I initiate a connection, I am prompted for my username and password, but it never completes.  As soon as a move my connection to a different network (mobile hotspot) it works fine, including when on other networks - any network so far except my hone network.

I have checked the logs, and I can't see anything which would explain why my VPN connection never succeeds.  Currently my Mac's IP address is not restricted by any filtering policy and I have excluded https from being filtered in transparent mode.

I do have UTM configured for inbound remote access (L2TP over IPSec), but don't know if this is interfering with the outbound connection.  I have looked at the Rulz thread, this didn't identify any issues.

Any suggestions on what to look for, or is it possible to run an OpenVPN connection through the VPN.  Any suggestions, pointers grealy appreciated. 



This thread was automatically locked due to age.
  • Finally resolved it - several years ago I had created another rule to drop 443/udp without logging because there was a significant amount of google related traffic going out on this port.  Unfortunately, this rule was earlier in the chain than the one I created for my laptop VPN connection.

    So, when creating rules, make them informative, use descriptive definition names and be consistent - this will go a long way to troubleshooting issues on a firewall that has been installed for several years when you may not remember the reasons for adding rules in the past.  

    Now time to go and eat some humble pie.

  • Hi, Martin, and welcome to the UTM Community!

    Thanks for turning a lemon into lemonade by coming back with a straightforward reminder for everyone.

    Cheers - Bob