Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN connects, but no data.

About a year ago, My VPN connections worked fine. After letting updates collect (9), I recently did all updates, and I'm at 9.409-9. I haven't needed to use the VPN in a while, but just tried it today. Didn't work. It would connect, but wouldn't transfer any data. I updated the config, and then the client, but even though it said it was connected, I couldn't make a remote desktop or ping connection. I downloaded and installed the package to a fresh install of Windows 8.1, and it still didn't work. Oddly, I updated the config on my Android phone, and I could use Remote Desktop through my phone, so the VPN works fine on my phone.

Any ideas how to fix?

Below is the log:

Tue Jan 24 18:08:48 2017 OpenVPN 2.3.8 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Jun 25 2016
Tue Jan 24 18:08:48 2017 library versions: OpenSSL 1.0.1t  3 May 2016, LZO 2.09
Enter Management Password:
Tue Jan 24 18:08:48 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Tue Jan 24 18:08:48 2017 Need hold release from management interface, waiting...
Tue Jan 24 18:08:49 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Tue Jan 24 18:08:49 2017 MANAGEMENT: CMD 'state on'
Tue Jan 24 18:08:49 2017 MANAGEMENT: CMD 'log all on'
Tue Jan 24 18:08:49 2017 MANAGEMENT: CMD 'hold off'
Tue Jan 24 18:08:49 2017 MANAGEMENT: CMD 'hold release'
Tue Jan 24 18:09:00 2017 MANAGEMENT: CMD 'username "Auth" "Joseph"'
Tue Jan 24 18:09:00 2017 MANAGEMENT: CMD 'password [...]'
Tue Jan 24 18:09:01 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Jan 24 18:09:01 2017 MANAGEMENT: >STATE:1485299341,RESOLVE,,,,,,
Tue Jan 24 18:09:01 2017 UDPv4 link local: [undef]
Tue Jan 24 18:09:01 2017 UDPv4 link remote: [AF_INET]24.184.129.39:443
Tue Jan 24 18:09:01 2017 MANAGEMENT: >STATE:1485299341,WAIT,,,,,,
Tue Jan 24 18:09:01 2017 MANAGEMENT: >STATE:1485299341,AUTH,,,,,,
Tue Jan 24 18:09:01 2017 TLS: Initial packet from [AF_INET]24.184.129.39:443, sid=38dd87f7 fe733cf7
Tue Jan 24 18:09:01 2017 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Tue Jan 24 18:09:01 2017 VERIFY OK: depth=1, C=us, L=Jackson, O=Western Technologies, CN=Western Technologies VPN CA, emailAddress=Joseph@mydomain.com
Tue Jan 24 18:09:01 2017 VERIFY X509NAME OK: C=us, L=Jackson, O=Western Technologies, CN=office.Westerntechnologies.com, emailAddress=Joseph@mydomain.com
Tue Jan 24 18:09:01 2017 VERIFY OK: depth=0, C=us, L=Jackson, O=Western Technologies, CN=office.Westerntechnologies.com, emailAddress=Joseph@mydomain.com
Tue Jan 24 18:09:01 2017 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jan 24 18:09:01 2017 Data Channel Encrypt: Using 128 bit message hash 'MD5' for HMAC authentication
Tue Jan 24 18:09:01 2017 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jan 24 18:09:01 2017 Data Channel Decrypt: Using 128 bit message hash 'MD5' for HMAC authentication
Tue Jan 24 18:09:01 2017 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Jan 24 18:09:01 2017 [office.Westerntechnologies.com] Peer Connection Initiated with [AF_INET]24.184.129.39:443
Tue Jan 24 18:09:02 2017 MANAGEMENT: >STATE:1485299342,GET_CONFIG,,,,,,
Tue Jan 24 18:09:03 2017 SENT CONTROL [office.Westerntechnologies.com]: 'PUSH_REQUEST' (status=1)
Tue Jan 24 18:09:03 2017 PUSH: Received control message: 'PUSH_REPLY,ifconfig-ipv6 fd32:5a88:8e98:2::1000/64 fd32:5a88:8e98:2::1,route-gateway 10.242.2.1,tun-ipv6,route-gateway 10.242.2.1,topology subnet,ping 10,ping-restart 120,redirect-gateway def1 ipv6,route-ipv6 ::/1,route-ipv6 8000::/1,dhcp-option DNS 8.8.8.8,dhcp-option DNS 192.168.1.1,dhcp-option DOMAIN office.Westerntechnologies.com,ifconfig 10.242.2.2 255.255.255.0'
Tue Jan 24 18:09:03 2017 Options error: unknown --redirect-gateway flag: ipv6
Tue Jan 24 18:09:03 2017 OPTIONS IMPORT: timers and/or timeouts modified
Tue Jan 24 18:09:03 2017 OPTIONS IMPORT: --ifconfig/up options modified
Tue Jan 24 18:09:03 2017 OPTIONS IMPORT: route options modified
Tue Jan 24 18:09:03 2017 OPTIONS IMPORT: route-related options modified
Tue Jan 24 18:09:03 2017 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Jan 24 18:09:03 2017 ROUTE_GATEWAY 192.168.8.1/255.255.255.0 I=10 HWADDR=24:0a:64:72:fb:b3
Tue Jan 24 18:09:03 2017 ROUTE6: default_gateway=UNDEF
Tue Jan 24 18:09:03 2017 open_tun, tt->ipv6=1
Tue Jan 24 18:09:03 2017 TAP-WIN32 device [Ethernet 2] opened: \\.\Global\{8171D0C5-F33E-4591-87AE-064FEDD0170C}.tap
Tue Jan 24 18:09:03 2017 TAP-Windows Driver Version 9.21
Tue Jan 24 18:09:03 2017 Set TAP-Windows TUN subnet mode network/local/netmask = 10.242.2.0/10.242.2.2/255.255.255.0 [SUCCEEDED]
Tue Jan 24 18:09:03 2017 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.242.2.2/255.255.255.0 on interface {8171D0C5-F33E-4591-87AE-064FEDD0170C} [DHCP-serv: 10.242.2.254, lease-time: 31536000]
Tue Jan 24 18:09:03 2017 Successful ARP Flush on interface [9] {8171D0C5-F33E-4591-87AE-064FEDD0170C}
Tue Jan 24 18:09:03 2017 do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1
Tue Jan 24 18:09:03 2017 MANAGEMENT: >STATE:1485299343,ASSIGN_IP,,10.242.2.2,,,,,fd32:5a88:8e98:2::1000
Tue Jan 24 18:09:03 2017 add_route_ipv6(fd32:5a88:8e98:2::/64 -> fd32:5a88:8e98:2::1000 metric 0) dev Ethernet 2
Tue Jan 24 18:09:07 2017 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Tue Jan 24 18:09:07 2017 MANAGEMENT: >STATE:1485299347,ADD_ROUTES,,,,,,
Tue Jan 24 18:09:07 2017 C:\Windows\system32\route.exe ADD 24.184.129.39 MASK 255.255.255.255 192.168.8.1
Tue Jan 24 18:09:07 2017 Route addition via service succeeded
Tue Jan 24 18:09:07 2017 add_route_ipv6(::/1 -> fd32:5a88:8e98:2::1 metric -1) dev Ethernet 2
Tue Jan 24 18:09:07 2017 add_route_ipv6(8000::/1 -> fd32:5a88:8e98:2::1 metric -1) dev Ethernet 2
Tue Jan 24 18:09:07 2017 Initialization Sequence Completed
Tue Jan 24 18:09:07 2017 MANAGEMENT: >STATE:1485299347,CONNECTED,SUCCESS,10.242.2.2,24.184.129.39,443,,,fd32:5a88:8e98:2::1000

 

----------------------------

 



This thread was automatically locked due to age.
Parents
  • Hi Rchadwick,

    Show me the SSL VPN configurations in UTM and few lines from packetfilter.log which drops the RDP traffic for the VPN clients.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Thanks for the response. I looked in the Firewall log, but saw nothing while connecting the VPN, or while trying to use it. This is what I saw before I connected:

    2017:01:25-12:08:05 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:05 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="00:01:5c:95:fa:46" dstmac="00:0c:29:ca:94:b7" srcip="80.98.11.136" dstip="24.184.129.39" proto="6" length="44" tos="0x00" prec="0x00" ttl="50" srcport="59767" dstport="23" tcpflags="SYN" 
    2017:01:25-12:08:07 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:09 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:16 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:18 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:20 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:22 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:24 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:26 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:33 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 
    2017:01:25-12:08:35 office ulogd[6674]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="00:12:12:34:da:bb" dstmac="00:0c:29:ca:94:ad" srcip="192.168.1.170" dstip="192.168.1.1" proto="1" length="356" tos="0x10" prec="0xc0" ttl="64" type="3" code="3" 

    Here is text of the VPN config:

    Interface address:Any
    Protocol: UDP        
    Port: 443    
    Override hostname: office.mydomain.com
    Pool network: VPN Pool (SSL)

    Encryption algorithm:    AES-128-CBC    
    Authentication algorithm:    MD5    
    Key size:        1024 bit
    Server certificate:    local X509 Cert    
    Key lifetime:    28800            seconds    

    Compress SSL VPN traffic is checked

    Users and groups:
    admin
    Jack
    Sophie

    Local Networks:
    Any
    Any IPv4
    External (WAN) (Network)
    Internal (Network)

    Automatic firewall rules is checked


    Thanks!


  • Hi RChadwick,

    In the Local Network, just add Internal (Network) and Internet object if you need a full tunnel. Remove the other definitions. Uncheck "Compress SSL VPN traffic". Finally, download a fresh config file from the user portal and connect to the SSL VPN.

    Any help?

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • That seems to have worked!

    The only problem I'm having now is that Internet doesn't work I can acesss computers on the remote network, but just get timeouts if I try to go anywhere on the Internet. I have tied from two computers, including a fresh download and install of the client and config.

  • Nevermind about the Internet. Seems some Firewall and Masquerading rules got wiped out after doing upgrades. Thanks again!

Reply Children
No Data