Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.500 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-15-2009, 04:57 PM
gnomme's Avatar
Member
 
Join Date: Mar 2009
Posts: 88
Default [7.450][DUPE] - BUG: Remote Desktop ssl tunnel

If IPS is enabled remote desktop connections trough SSL VPN do not work. If I stop the service and try again It works
__________________
Life is a giant network! Choose the best path!
  #2 (permalink)  
Old 06-15-2009, 05:43 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,378
Default

Gnomme, do you mean stop/start IPS while you have an SSL VPN session running, or that it only works when IPS is stopped?

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
  #3 (permalink)  
Old 06-15-2009, 05:56 PM
gnomme's Avatar
Member
 
Join Date: Mar 2009
Posts: 88
Default

Quote:
Originally Posted by BAlfson View Post
Gnomme, do you mean stop/start IPS while you have an SSL VPN session running, or that it only works when IPS is stopped?

Cheers - Bob
yes! however some hours later when I make another vpn connection the same problem happens
__________________
Life is a giant network! Choose the best path!
  #4 (permalink)  
Old 06-15-2009, 06:00 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,378
Default

"Yes" ???

Is it "A" or "B" ?

A. It works after you "stop/start IPS while you have an SSL VPN session running"

B. "it only works when IPS is stopped"

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
  #5 (permalink)  
Old 06-15-2009, 06:03 PM
gnomme's Avatar
Member
 
Join Date: Mar 2009
Posts: 88
Default

sorry...stop/start
__________________
Life is a giant network! Choose the best path!
  #6 (permalink)  
Old 06-16-2009, 02:35 AM
Senior Member
 
Join Date: Jul 2008
Posts: 121
Default

hmm, I use TS over ssl vpn daily and I don't have this problem on my beta instances. Did you see anything in packet filter logs?
  #7 (permalink)  
Old 06-16-2009, 03:31 AM
Wizard
 
Join Date: Oct 2005
Posts: 2,428
Default

Check your IPS logs; chances are you are experiencing a IPS rule that's being falsely triggered; when you see the rule sid in the log, just add it to the disabled rule list in the advanced tab under Intrusion Protection configuration.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #8 (permalink)  
Old 06-16-2009, 02:41 PM
Senior Member
 
Join Date: Nov 2008
Posts: 169
Default

@gnomme
Can you please specify which rules are causing the drops?
Just posting the SIDs would be great, thanks.
__________________
Astaro AG
  #9 (permalink)  
Old 06-16-2009, 07:34 PM
gnomme's Avatar
Member
 
Join Date: Mar 2009
Posts: 88
Default

I thont know wich rule is...I used VPN a lot in my previous version of ASG with no problem. the configurations was imported from the older
__________________
Life is a giant network! Choose the best path!
  #10 (permalink)  
Old 06-16-2009, 10:40 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,378
Default

Gnomme, ee-tra wants you to look in your Intrusion Protection log to see what rules are listed when this traffic is blocked.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:22 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.