Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN Cannot Connect

I have just setup SG 125 using UTM 9.3.  I have been trying to get the SSL VPN to work and been unsuccessful.  I had help directly from Sophos for the setup as well as I have double-checked my setup from the guides.  Our main DNS/AD server is a Small business Server and so we use .internal extension for most of our naming conventions and the UTM is no exception.  So the hostname is utm.domain.internal.  Trying to login using Tunnelblick because we use Macs I can connect while on the LAN but offsite the hostname fails to resolve and I assume that this is because of the .internal extension and therefore this cannot be found publicly.  I then put in the internal IP address of the UTM in the override hosts line and when I tried to connect offsite I get AF_INET IP of UTM:4443 failed will try again in 5 seconds.  I am not seeing anything in any of the logs that is pointing me in the right direction.  I can provide more info as needed but am wondering if someone can help point me in the right direction.  One thing about Small Business Server is that creating new A records results in the .internal extension.  We have mail.domain.com and remote.domain.com for our OWA and RWA as zones.  I don't like to make too many changes to SBS setup because it causes problems with the way the entire system works together.



This thread was automatically locked due to age.
Parents
  • Assuming that you were just using the VPN connection in the LAN for test purposes only, in Override Hostname you need to put the FQDN that is used by external DNS that points to the WAN of the UTM or the external WAN address of the UTM. Otherwise, how are the clients to know what the WAN address of the UTM is?
    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1
  • Hi Scott, so because of our sbs setup we don't have just one FQDN. We use mail. and remote. suffixes for the .com address and everything else is on .internal. I haven't tried to put in our external IP address for the override hostname so I will try that. Thanks. Otherwise I guess I will need to create a new DNS zone for the UTM. And I'm not feeling like that is something I will tackle without some technical help since I haven't had to do much with DNS.
Reply
  • Hi Scott, so because of our sbs setup we don't have just one FQDN. We use mail. and remote. suffixes for the .com address and everything else is on .internal. I haven't tried to put in our external IP address for the override hostname so I will try that. Thanks. Otherwise I guess I will need to create a new DNS zone for the UTM. And I'm not feeling like that is something I will tackle without some technical help since I haven't had to do much with DNS.
Children
  • Hi Lianne,

    1. Create new A host DNS record in public DNS zone for vpn access that points to WAN IP address of UTM device.
    2. Define that FQDN in Override Hostname SSL VPN settings.
    3. Download SSL VPN packages from UTM Webadmin console and distribute it to end users.