Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Please help: No SSL VPN Connection to UTM 9.505-4

Hi,

UTM VPN Connection makes me crazy again and again.

Do, I donwloaded the client to my Windows PC, installed and restarted.

Still can get no connection to the Server.

Any help appreciated

Tom

-----------------------------------------------------------------------------------------

Here is the Server log:

2017:11:07-12:19:55 cUTM openvpn[6652]: MULTI: multi_create_instance called
2017:11:07-12:19:55 cUTM openvpn[6652]: Re-using SSL/TLS context
2017:11:07-12:19:55 cUTM openvpn[6652]: LZO compression initialized
2017:11:07-12:19:55 cUTM openvpn[6652]: Control Channel MTU parms [ L:1560 D:1210 EF:40 EB:0 ET:0 EL:3 ]
2017:11:07-12:19:55 cUTM openvpn[6652]: Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:143 ET:0 EL:3 AF:3/1 ]
2017:11:07-12:19:55 cUTM openvpn[6652]: Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2017:11:07-12:19:55 cUTM openvpn[6652]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2017:11:07-12:19:55 cUTM openvpn[6652]: Local Options hash (VER=V4): 'b695cb4a'
2017:11:07-12:19:55 cUTM openvpn[6652]: Expected Remote Options hash (VER=V4): 'bc07730e'
2017:11:07-12:19:55 cUTM openvpn[6652]: TCP connection established with [AF_INET]89.207.88.131:55464 (via [AF_INET]88.216.226.235:445)
2017:11:07-12:19:55 cUTM openvpn[6652]: TCPv4_SERVER link local: [undef]
2017:11:07-12:19:55 cUTM openvpn[6652]: TCPv4_SERVER link remote: [AF_INET]89.207.88.131:55464
2017:11:07-12:19:55 cUTM openvpn[6652]: 89.207.88.131:55464 Connection reset, restarting [0]
2017:11:07-12:19:55 cUTM openvpn[6652]: 89.207.88.131:55464 SIGUSR1[soft,connection-reset] received, client-instance restarting
2017:11:07-12:19:55 cUTM openvpn[6652]: TCP/UDP: Closing socket
2017:11:07-12:19:55 cUTM openvpn[6652]: MULTI: multi_create_instance called
2017:11:07-12:19:55 cUTM openvpn[6652]: Re-using SSL/TLS context
2017:11:07-12:19:55 cUTM openvpn[6652]: LZO compression initialized
2017:11:07-12:19:55 cUTM openvpn[6652]: Control Channel MTU parms [ L:1560 D:1210 EF:40 EB:0 ET:0 EL:3 ]
2017:11:07-12:19:55 cUTM openvpn[6652]: Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:143 ET:0 EL:3 AF:3/1 ]
2017:11:07-12:19:55 cUTM openvpn[6652]: Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2017:11:07-12:19:55 cUTM openvpn[6652]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2017:11:07-12:19:55 cUTM openvpn[6652]: Local Options hash (VER=V4): 'b695cb4a'
2017:11:07-12:19:55 cUTM openvpn[6652]: Expected Remote Options hash (VER=V4): 'bc07730e'
2017:11:07-12:19:55 cUTM openvpn[6652]: TCP connection established with [AF_INET]89.207.88.131:55470 (via [AF_INET]88.216.226.235:445)
2017:11:07-12:19:55 cUTM openvpn[6652]: TCPv4_SERVER link local: [undef]
2017:11:07-12:19:55 cUTM openvpn[6652]: TCPv4_SERVER link remote: [AF_INET]89.207.88.131:55470
2017:11:07-12:19:55 cUTM openvpn[6652]: 89.207.88.131:55470 WARNING: Bad encapsulated packet length from peer (0), which must be > 0 and <= 1563 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2017:11:07-12:19:55 cUTM openvpn[6652]: 89.207.88.131:55470 Connection reset, restarting [0]
2017:11:07-12:19:55 cUTM openvpn[6652]: 89.207.88.131:55470 SIGUSR1[soft,connection-reset] received, client-instance restarting
2017:11:07-12:19:55 cUTM openvpn[6652]: TCP/UDP: Closing socket
2017:11:07-12:19:58 cUTM openvpn[6652]: MULTI: multi_create_instance called
2017:11:07-12:19:58 cUTM openvpn[6652]: Re-using SSL/TLS context
2017:11:07-12:19:58 cUTM openvpn[6652]: LZO compression initialized
2017:11:07-12:19:58 cUTM openvpn[6652]: Control Channel MTU parms [ L:1560 D:1210 EF:40 EB:0 ET:0 EL:3 ]
2017:11:07-12:19:58 cUTM openvpn[6652]: Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:143 ET:0 EL:3 AF:3/1 ]
2017:11:07-12:19:58 cUTM openvpn[6652]: Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2017:11:07-12:19:58 cUTM openvpn[6652]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2017:11:07-12:19:58 cUTM openvpn[6652]: Local Options hash (VER=V4): 'b695cb4a'
2017:11:07-12:19:58 cUTM openvpn[6652]: Expected Remote Options hash (VER=V4): 'bc07730e'
2017:11:07-12:19:58 cUTM openvpn[6652]: TCP connection established with [AF_INET]89.207.88.131:55792 (via [AF_INET]88.216.226.235:445)
2017:11:07-12:19:58 cUTM openvpn[6652]: TCPv4_SERVER link local: [undef]
2017:11:07-12:19:58 cUTM openvpn[6652]: TCPv4_SERVER link remote: [AF_INET]89.207.88.131:55792
2017:11:07-12:19:58 cUTM openvpn[6652]: 89.207.88.131:55792 WARNING: Bad encapsulated packet length from peer (0), which must be > 0 and <= 1563 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2017:11:07-12:19:58 cUTM openvpn[6652]: 89.207.88.131:55792 Connection reset, restarting [0]
2017:11:07-12:19:58 cUTM openvpn[6652]: 89.207.88.131:55792 SIGUSR1[soft,connection-reset] received, client-instance restarting
2017:11:07-12:19:58 cUTM openvpn[6652]: TCP/UDP: Closing socket

 

 

----------------------------------------------------------------------------------------

And her the Client: 

Tue Nov 07 12:18:36 2017 DEPRECATED OPTION: --tls-remote, please update your configuration
Tue Nov 07 12:18:36 2017 OpenVPN 2.3.8 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Jun 23 2017
Tue Nov 07 12:18:36 2017 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.09
Tue Nov 07 12:18:36 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Tue Nov 07 12:18:36 2017 Need hold release from management interface, waiting...
Tue Nov 07 12:18:36 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Tue Nov 07 12:18:36 2017 MANAGEMENT: CMD 'state on'
Tue Nov 07 12:18:36 2017 MANAGEMENT: CMD 'log all on'
Tue Nov 07 12:18:36 2017 MANAGEMENT: CMD 'hold off'
Tue Nov 07 12:18:36 2017 MANAGEMENT: CMD 'hold release'
Tue Nov 07 12:18:42 2017 MANAGEMENT: CMD 'username "Auth" "tho"'
Tue Nov 07 12:18:42 2017 MANAGEMENT: CMD 'password [...]'
Tue Nov 07 12:18:42 2017 MANAGEMENT: CMD 'proxy NONE '
Tue Nov 07 12:18:44 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Nov 07 12:18:44 2017 Attempting to establish TCP connection with [AF_INET]88.216.226.235:445 [nonblock]
Tue Nov 07 12:18:44 2017 MANAGEMENT: >STATE:1510053524,TCP_CONNECT,,,,,,
Tue Nov 07 12:18:54 2017 TCP: connect to [AF_INET]88.216.226.235:445 failed, will try again in 5 seconds: Das System hat versucht, einem Verzeichnis, das sich auf einem mit JOIN zugeordneten Laufwerk befindet, ein Laufwerk mit SUBST zuzuordnen.
Tue Nov 07 12:18:54 2017 SIGUSR1[soft,init_instance] received, process restarting
Tue Nov 07 12:18:54 2017 MANAGEMENT: >STATE:1510053534,RECONNECTING,init_instance,,,,,
Tue Nov 07 12:18:54 2017 Restart pause, 5 second(s)
Tue Nov 07 12:18:59 2017 MANAGEMENT: CMD 'proxy NONE '
Tue Nov 07 12:19:00 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Nov 07 12:19:00 2017 Attempting to establish TCP connection with [AF_INET]88.216.226.235:445 [nonblock]
Tue Nov 07 12:19:00 2017 MANAGEMENT: >STATE:1510053540,TCP_CONNECT,,,,,,
Tue Nov 07 12:19:10 2017 TCP: connect to [AF_INET]88.216.226.235:445 failed, will try again in 5 seconds: Das System hat versucht, einem Verzeichnis, das sich auf einem mit JOIN zugeordneten Laufwerk befindet, ein Laufwerk mit SUBST zuzuordnen.
Tue Nov 07 12:19:10 2017 SIGUSR1[soft,init_instance] received, process restarting
Tue Nov 07 12:19:10 2017 MANAGEMENT: >STATE:1510053550,RECONNECTING,init_instance,,,,,
Tue Nov 07 12:19:10 2017 Restart pause, 5 second(s)
Tue Nov 07 12:19:15 2017 MANAGEMENT: CMD 'proxy NONE '
Tue Nov 07 12:19:16 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Nov 07 12:19:16 2017 Attempting to establish TCP connection with [AF_INET]88.216.226.235:445 [nonblock]
Tue Nov 07 12:19:16 2017 MANAGEMENT: >STATE:1510053556,TCP_CONNECT,,,,,,



This thread was automatically locked due to age.
Parents
  • Tom, there's a bug in 9.505 that disrupts VPNs if you've re-generated the Proxy CA for Web Filtering.  Make a configuration backup and then try restoring an older backup from when this worked.  You might want to re-download the configuration to your PC.  Did that fix you up?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Tom, there's a bug in 9.505 that disrupts VPNs if you've re-generated the Proxy CA for Web Filtering.  Make a configuration backup and then try restoring an older backup from when this worked.  You might want to re-download the configuration to your PC.  Did that fix you up?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?