Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange skype and socks5 behavior

Have configured Skype to use Socks5 with "Automatic detect settings".On the client Win 10 machine I have a proxy agent which sets system proxy address depending on network.

When starting Skype, I get this in the UTM socks log

2016:07:07-15:39:34 fw sockd[29168]: info: pass(1): tcp/accept [: 192.168.1.10.65433 192.168.1.1.1080
2016:07:07-15:39:34 fw sockd[29168]: info: block(1): tcp/accept ]: 192.168.1.10.65433 192.168.1.1.1080: error after having read 24 bytes: access denied by AUA

What have I done wrong?



This thread was automatically locked due to age.
  • Erik, I use SOCKS5 with Skype, but configure it to use the proxy on port 1080 instead of using automatic.  Do you have the credentials for your UTM user in the connection configuration in Skype?  My guess would be that you need to do a manual configuration in Skype with those because your Skype credentials are different.  Just a guess based on the AUA comment in the log.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • The user account is set and is working for other services, like Sophos Authentication Agent, so the credentials is working,

    The reason for using automatic mode in skype is that when i am connecting to the Internet form other locations than home, like mobile broadband, I do not want to configure it manually.


    I am also using a proxy confifuration application on the client, setting the system proxy setting, just for using Skype in automatic mode. That part is working according to the log.

    Just tried manually settings,

    2016:07:09-19:32:44 fw sockd[29168]: info: pass(1): tcp/accept [: 192.168.1.10.49361 192.168.1.1.1080
    2016:07:09-19:32:44 fw sockd[29168]: info: block(1): tcp/accept ]: 192.168.1.10.49361 192.168.1.1.1080: error after having read 24 bytes: access denied by AUA

    I am also using a proxy configuration application on the client, setting the system proxy setting, just for using Skype in automatic mode. That part is working according to the log.

    Strange...

  • Just tried to to use manual mode in skype using port 1080 and I am getting the same result in the Socks log :(

    2016:08:05-08:39:28 fw sockd[4396]: info: pass(1): tcp/accept [: 192.168.1.10.62573 192.168.1.1.1080
    2016:08:05-08:39:28 fw sockd[4396]: info: block(1): tcp/accept ]: 192.168.1.10.62573 192.168.1.1.1080: error after having read 26 bytes: access denied by AUA

    I am not using One Time Password (OTP)

  • Hello Erik, hello BAlfson,

    today i got the similar error:

    SOCKS-Log:

    2016:09:12-13:12:35 astaro8 sockd[18420]: info: dante/server[1] v1.3.2 running
    2016:09:12-13:13:37 astaro8 sockd[18422]: info: pass(1): tcp/accept [: 192.168.55.77.64303 192.168.55.248.1080
    2016:09:12-13:13:37 astaro8 sockd[18422]: info: block(1): tcp/accept ]: 192.168.55.77.64303 192.168.55.248.1080: error after having read 25 bytes: access denied by AUA
    USERAUTH-Log:
    2016:09:12-13:13:37 astaro8 aua[18529]: id="3005" severity="warn" sys="System" sub="auth" name="Authentication failed" srcip="192.168.55.77" host="" user="cioware" caller="socks" reason="DENIED"
    2016:09:12-13:13:42 astaro8 aua[18536]: id="3005" severity="warn" sys="System" sub="auth" name="Authentication failed" srcip="192.168.55.77" host="" user="cioware" caller="socks" reason="DENIED"
    2016:09:12-13:13:42 astaro8 aua[18538]: id="3005" severity="warn" sys="System" sub="auth" name="Authentication failed" srcip="192.168.55.77" host="" user="cioware" caller="socks" reason="DENIED"
    In Skype the SOCKS5-Proxy is done with individual configuration.
    Is there any conclusion or solution ?
    Thanks
    Martin
  • Hi, Martin, and welcome to the UTM Community!

    How is the authentication being done?  Is this on a Windows server for a user in Active Directory or is this a Local user on the UTM?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    thank you for responsding. That must be told first :-)

    the user i´m using for authentication is a local UTM User.

    Regards Martin

  • Please show a picture of the SOCKS configuration in WebAdmin.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob, here it is:

    and the User-Config:

    Cheers Martin

  • That all looks good, Martin.  WHat happens if you now configure Skype like this?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I can join this discussion too, I am experiencing the same problem since several months ago.

    If I turn off passwords in the UTM socks proxy config, forcing it to SOCKS4, the socks proxy is working without the "error after having read 24 bytes: access denied by AUA" error. The socks proxy log is now showing successful connections.

    Using SOCKS 4 instead of socks 5 could be a solution? However, I am not certain of which functionality I loose besides not have to set username and password?

    Then I am running into the next problem :(

    Since I am also using https-proxy, Skype cannot log in my Skype user. The blue connect icon in Skype turns in eternity. If I turn off the https proxy and opens https for outgoing traffic Skype successfully logs in and all is working. But deactivation of the https-proxy is not the final solution for me so I am stranded here.

    This is my exception for skype for web filtering:

    There should possibly be more people with the same problems? How have you configured UTM and Skype using https proxy?

    UTM v9.407-3

    Skype v7.28.0.101