Hi I was wondering if anyone could help me out?
I had to restore our UTM from a backup this morning, I used one from early hours this morning so its not an old backup. But since doing this our SSL VPN clients cannot connect anymore, I cant see whats wrong as nothing in the config has changed. Here is a log from a clients SSL VPN: -
Sat Jun 20 14:37:29 2015 OpenVPN 2.3.0 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Mar 23 2015
Enter Management Password:
Sat Jun 20 14:37:29 2015 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Sat Jun 20 14:37:29 2015 Need hold release from management interface, waiting...
Sat Jun 20 14:37:30 2015 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Sat Jun 20 14:37:30 2015 MANAGEMENT: CMD 'state on'
Sat Jun 20 14:37:31 2015 MANAGEMENT: CMD 'log all on'
Sat Jun 20 14:37:31 2015 MANAGEMENT: CMD 'hold off'
Sat Jun 20 14:37:31 2015 MANAGEMENT: CMD 'hold release'
Sat Jun 20 14:37:42 2015 MANAGEMENT: CMD 'username "Auth" "johnkenny"'
Sat Jun 20 14:37:42 2015 MANAGEMENT: CMD 'password [...]'
Sat Jun 20 14:37:42 2015 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page).
Sat Jun 20 14:37:42 2015 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Sat Jun 20 14:37:42 2015 Socket Buffers: R=[65536->65536] S=[64512->64512]
Sat Jun 20 14:37:42 2015 Attempting to establish TCP connection with [AF_INET]77.107.146.209:443 [nonblock]
Sat Jun 20 14:37:42 2015 MANAGEMENT: >STATE:1434807462,TCP_CONNECT,,,
Sat Jun 20 14:37:43 2015 TCP connection established with [AF_INET]77.107.146.209:443
Sat Jun 20 14:37:43 2015 TCPv4_CLIENT link local: [undef]
Sat Jun 20 14:37:43 2015 TCPv4_CLIENT link remote: [AF_INET]77.107.146.209:443
Sat Jun 20 14:37:43 2015 MANAGEMENT: >STATE:1434807463,WAIT,,,
Sat Jun 20 14:37:43 2015 MANAGEMENT: >STATE:1434807463,AUTH,,,
Sat Jun 20 14:37:43 2015 TLS: Initial packet from [AF_INET]xx.xx.xx.209:443, sid=0331a78b 4b66e0f5
Sat Jun 20 14:37:43 2015 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Sat Jun 20 14:37:43 2015 VERIFY ERROR: depth=0, error=unable to get local issuer certificate: C=uk, CN=xx.xx.xx.209
Sat Jun 20 14:37:43 2015 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Sat Jun 20 14:37:43 2015 TLS Error: TLS object -> incoming plaintext read error
Sat Jun 20 14:37:43 2015 TLS Error: TLS handshake failed
Sat Jun 20 14:37:43 2015 Fatal TLS error (check_tls_errors_co), restarting
Sat Jun 20 14:37:43 2015 SIGUSR1[soft,tls-error] received, process restarting
Sat Jun 20 14:37:43 2015 MANAGEMENT: >STATE:1434807463,RECONNECTING,tls-error,,
Sat Jun 20 14:37:43 2015 Restart pause, 5 second(s)
Sat Jun 20 14:37:48 2015 SIGTERM[hard,init_instance] received, process exiting
Sat Jun 20 14:37:48 2015 MANAGEMENT: >STATE:1434807468,EXITING,init_instance,,
I can see there is a cert verification error but im only using local users for the SSL VPN not AD users and the cert was generated on the UTM aswell.
What could be causing this?
Many thanks in advance,
JK
This thread was automatically locked due to age.