Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.000 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-09-2007, 06:01 PM
lantech's Avatar
Member
 
Join Date: Nov 2006
Posts: 75
Default OpenVPN ssl issues

I haven't been able to get the ssl vpn to work. I'm not sure its configured correctly with the lack of documentation.

Here is what I am getting in the log.

2007:01:09-09:44:53 (none) openvpn[5271]: TCP connection established with ******xx:61688
2007:01:09-09:44:53 (none) openvpn[5271]: Socket Buffers: R=[131072->131072] S=[131072->131072]
2007:01:09-09:44:53 (none) openvpn[5271]: TCPv4_SERVER link local: [undef]
2007:01:09-09:44:53 (none) openvpn[5271]: TCPv4_SERVER link remote: ******xx:61688
2007:01:09-09:44:53 (none) openvpn[5271]: ******x:61688 WARNING: Bad encapsulated packet length from peer (32829), which must be > 0 and <= 1555 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attemping restart...]
2007:01:09-09:44:53 (none) openvpn[5271]: ******x:61688 Connection reset, restarting [0]
2007:01:09-09:44:53 (none) openvpn[5271]: *********:61688 SIGUSR1[soft,connection-reset] received, client-instance restarting
2007:01:09-09:44:53 (none) openvpn[5271]: TCP/UDP: Closing socket

windows xp sp2 client
  #2 (permalink)  
Old 01-10-2007, 05:47 PM
Junior Member
 
Join Date: Nov 2006
Posts: 12
Default

Quote:
2007:01:09-09:44:53 (none) openvpn[5271]: ******x:61688 WARNING: Bad encapsulated packet length from peer (32829), which must be > 0 and <= 1555 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attemping restart...]
Probier den angebotenen Fix doch einfach mal aus.

mfg
cane
  #3 (permalink)  
Old 01-10-2007, 06:19 PM
lantech's Avatar
Member
 
Join Date: Nov 2006
Posts: 75
Default

I looked into that a little and didn't find where to actually change those settings. I am running windows xp SP2 on the client side. Suggestions where to look?
  #4 (permalink)  
Old 01-11-2007, 04:14 PM
Senior Member
 
Join Date: Mar 2003
Posts: 184
Default

Please check the MTU on the virtual network adapter:
- Right-click on "My network places", select "Properties"
- Richt-click on "Astaro SSL VPN adapter", select "Properties"
- Click on "Configure"
- Select "Advanced" and click on "MTU".

Which MTU value do you get?

Stephan
  #5 (permalink)  
Old 01-11-2007, 05:53 PM
lantech's Avatar
Member
 
Join Date: Nov 2006
Posts: 75
Default

I'm not even getting to the point where the ssl vpn adapter is installed. I can get to the management site at ***:4444, but I can't get to an actual page where I could even get the SSL adapter download.
  #6 (permalink)  
Old 01-11-2007, 06:00 PM
Senior Member
 
Join Date: Mar 2003
Posts: 184
Default

You need to enable the user portal in WebAdmin (Management->End-User-Portal), then connect to the user portal (default on standard HTTPS port) with the VPN user and download the package there.

Stephan
  #7 (permalink)  
Old 02-05-2007, 10:08 PM
lantech's Avatar
Member
 
Join Date: Nov 2006
Posts: 75
Red face OpenSSL vpn resolved

Quote:
Originally Posted by Stephan_Scholz View Post
You need to enable the user portal in WebAdmin (Management->End-User-Portal), then connect to the user portal (default on standard HTTPS port) with the VPN user and download the package there.

Stephan
I missed that part. It's working now.

I would have assumed that the SSL VPN wouldn't require a client though. That really makes it no better than an IPSEC client except for fewer firewall issues. Doesn't help someone trying to connect from a different PC other than their own.
  #8 (permalink)  
Old 02-06-2007, 08:29 AM
Senior Member
 
Join Date: Mar 2003
Posts: 184
Default

Glad that it works now, thanks for reporting.

Actually other SSL VPN solutions come with a client, too (if they provide full network access, that is, and if you want to use local applications). It's only that they hide the installation better by installing an ActiveX control :-)

Stephan
  #9 (permalink)  
Old 02-06-2007, 02:57 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,431
Default

Quote:
Originally Posted by lantech View Post
I missed that part. It's working now.

I would have assumed that the SSL VPN wouldn't require a client though. That really makes it no better than an IPSEC client except for fewer firewall issues. Doesn't help someone trying to connect from a different PC other than their own.
I would point out that making it easy for clients to connect from a random PC (copy shop, coffee shop, etc.) is not a good idea... those types of public computers are favorite targets for keyloggers and other malware... I for one like the SSL VPN capability.
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:21 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.