Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN issue after UTM upgrade to 9.404-5

Hello,

after the UTM upgrade from 9.403-4 to 9.404-5 the SSL VPN connection is no longer working. I changed nothing on the configuration.

Now I get following error message:

...

2016:06:28-12:24:27 firewall openvpn[9229]: SENT CONTROL [firewall]: 'PUSH_REQUEST' (status=1)

2016:06:28-12:24:27 firewall openvpn[9229]: TCPv4_CLIENT WRITE [56] to [AF_INET]213.136.68.103:44344 (via [AF_INET]10.10.10.254:35371): P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=42
2016:06:28-12:24:27 firewall openvpn[9229]: TCPv4_CLIENT READ [22] from [AF_INET]213.136.68.103:44344 (via [AF_INET]10.10.10.254:35371): P_ACK_V1 kid=0 [ 5 ]
2016:06:28-12:24:27 firewall openvpn[9229]: TCPv4_CLIENT READ [466] from [AF_INET]213.136.68.103:44344 (via [AF_INET]10.10.10.254:35371): P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=452
2016:06:28-12:24:27 firewall openvpn[9229]: PUSH: Received control message: 'PUSH_REPLY,topology subnet,route-gateway 192.168.55.1,route 192.168.54.0 255.255.255.0,route 192.168.55.0 255.255.255.0,setenv-safe remote_network_1 192.168.54.0/24,setenv-safe remote_network_2 192.168.55.0/24,setenv-safe local_network_1 192.168.5.0/24,setenv-safe local_network_2 192.168.111.0/24,setenv-safe local_network_3 192.168.250.0/24,setenv-safe local_network_4 192.168.110.0/24,ifconfig 192.168.54.6 192.168.54.5'
2016:06:28-12:24:27 firewall openvpn[9229]: OPTIONS IMPORT: --ifconfig/up options modified
2016:06:28-12:24:27 firewall openvpn[9229]: OPTIONS IMPORT: route options modified
2016:06:28-12:24:27 firewall openvpn[9229]: OPTIONS IMPORT: route-related options modified
2016:06:28-12:24:27 firewall openvpn[9229]: OPTIONS IMPORT: environment modified
2016:06:28-12:24:27 firewall openvpn[9229]: ROUTE_GATEWAY 10.10.10.1/255.255.255.0 IFACE=eth0.10 HWADDR=00:15:5d:6f:14:09
2016:06:28-12:24:27 firewall openvpn[9229]: TUN/TAP device tun1 opened
2016:06:28-12:24:27 firewall openvpn[9229]: TUN/TAP TX queue length set to 100
2016:06:28-12:24:27 firewall openvpn[9229]: do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2016:06:28-12:24:27 firewall openvpn[9229]: /bin/ip link set dev tun1 up mtu 1500
2016:06:28-12:24:27 firewall openvpn[9229]: /bin/ip addr add dev tun1 192.168.54.6/11 broadcast 255.255.255.254
2016:06:28-12:24:27 firewall openvpn[9229]: /bin/ip route change dev tun1 192.168.54.4/11 proto 41 src 192.168.54.6
2016:06:28-12:24:27 firewall openvpn[9229]: MANAGEMENT: Client disconnected
2016:06:28-12:24:27 firewall openvpn[9229]: Linux ip route change failed: external program exited with error status: 2
2016:06:28-12:24:27 firewall openvpn[9229]: Exiting due to fatal error
2016:06:28-12:24:35 firewall openvpn[6482]: MANAGEMENT: Client disconnected

Because tun1 is not available I tryed to execute this command for a test on another interface and then I got following error message:

firewall:/var/sec/chroot-openvpn/etc/openvpn/conf.d # /bin/ip route change dev tun0 192.168.54.4/11 proto 41 src 192.168.54.6
RTNETLINK answers: Invalid argument

I hope you can help me!

Many Thanks!

Regards

Simon



This thread was automatically locked due to age.
Parents
  • Hi folks,

    I've got news from support (german).

    "das ist ein bekannter Fehler in der 9.404. Daher am besten IPSec Site2Site benutzen oder warten bis die 9.405 raus ist, damit sollte es behoben sein."

    wich means we should wait for 9.405.

    Greetings.

  • Up2Date 9.405005 package out now, no solution, same error.
    (Site2Site SSL from UTM to UTM)

    Site2site SSL Live log, just open it, no connection active:
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: MANAGEMENT: Client disconnected
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: Linux ip route change failed: external program exited with error status: 2
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: Exiting due to fatal error

    Interface tun0 is totally missing.

    By the way, how to install 9.403 if only ISO for 9.404-5.1 is available and buggy?

    Hitting the update button is killing the UTM. Backupfile from 9.4 cannot be imported to 9.3 which is the only working available ISO image for that case.

    Does anyone have the ISO of the 9.403-4?

    Regards

Reply
  • Up2Date 9.405005 package out now, no solution, same error.
    (Site2Site SSL from UTM to UTM)

    Site2site SSL Live log, just open it, no connection active:
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: MANAGEMENT: Client disconnected
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: Linux ip route change failed: external program exited with error status: 2
    2016:08:02-09:15:03 UTM_MPCA_DEMO openvpn[7305]: Exiting due to fatal error

    Interface tun0 is totally missing.

    By the way, how to install 9.403 if only ISO for 9.404-5.1 is available and buggy?

    Hitting the update button is killing the UTM. Backupfile from 9.4 cannot be imported to 9.3 which is the only working available ISO image for that case.

    Does anyone have the ISO of the 9.403-4?

    Regards

Children
No Data