Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN SSL Disconnect after 1 hour, PPTP or L2TP don't have problem

Since 15 days we began with this problem, all the ssl vpn clients are disconnect every hour, for example one client connects at 7:45 AM, another connects at 8:00 AM and the last at 8:05 AM, then at 8:31 AM o clock all clients are disconnected and the same situacion every hour.
We don´t have this problema with L2TP and PPTP protocols

We have UTM Model SG310 with firmware versión 9.405-5, and we use the client SSL VPN provided by Sophos.

I enabled debug in the log VPN SSL and this is the result:

[AF_INET]xxx.xxx.xxx.xxx:4443): P_DATA_V1 kid=0 DATA len=84
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: MANAGEMENT: Client connected from /var/run/openvpn_mgmt
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: MANAGEMENT: CMD 'kill AZuccarino'
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: AZuccarino/186.138.142.180:63623 SIGTERM[soft,] received, client-instance exiting
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: id="2202" severity="info" sys="SecureNet" sub="vpn" event="Connection terminated" username="azuccarino" variant="ssl" srcip="186.138.142.180" virtual_ip="10.1.104.5" rx="3631697" tx="9302906"
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: PLUGIN_CALL: POST /usr/lib/openvpn/plugins/openvpn-plugin-utm.so/PLUGIN_CLIENT_DISCONNECT status=0
2016:09:06-17:31:06 lasa999-1 openvpn[9174]: TCP/UDP: Closing socket

any idea about this problem?




This thread was automatically locked due to age.
Parents
  • Hi Andre,

    Where any changes made through the backend? Any cronjobs added? Are you authenticating with local users defined in UTM or the backend User. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Sachin, this issue was solved.
    I explain the situation and the solution.
    Ssl vpn local users are not disconnected. The problem only appeared with AD users.
    One Partner of sophos (Server Solution) had already had this problem, and he unmarked the options "Enable AD group membership background sync" and "Enable backend sync on login" (Under "Authentication Services / advanced") and the problem did not return to happen.
    I suppose a file that caches this information is corrupted.

    Thank you.

    Regards,

    Andrés.

  • Hi Andres,

    Exactly the direction we where heading towards. As I mentioned in my previous post whether the User where authenticated via backend server. 

    Hope to see you again. :)

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply Children
No Data