Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Other Astaro Products > Astaro Command Center (ACC)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-19-2009, 10:03 PM
Junior Member
 
Join Date: Apr 2009
Posts: 2
Default Cannot get remote sites connected to Command Center

Hello

We have numerous security gateways SSL vpn'd into a main security gateway. On the same network as the main security gateway we have a command center running. The remote devices are located behind third party firewalls, but we do have a full SSL tunnel connection to the devices.

Here is the issue we're having. The following message appears on all of the remote devices in the log when you try to enable centralized management. The main security gateway connects fine to the command center.


2009:04:19-22:56:13 r1004 device-agent[18380]: ACC connection failure, retrying (ip=10.30.100.170, port=4433). SSL-connect: 'IO::Socket::INET configuration failederror:00000000:lib(0):func(0):reason(0)'
2009:04:19-22:56:23 r1004 device-agent[18380]: ACC connection failure, retrying (ip=10.30.100.170, port=4433). SSL-connect: 'IO::Socket::INET configuration failederror:00000000:lib(0):func(0):reason(0)'


From a device on a remote network I can access without any issue and vice versa

https://10.30.100.170:4433
https://10.30.100.170:4422
https://10.30.100.170:4444

I have checked the packet filter logs, and just about everything else I can think of.

Does the command center work only when it is the gateway connected to a the wan on the remote network? Or will it work through an SSL tunnel?

Thank you in advance

Last edited by dan_cytexone; 04-19-2009 at 10:06 PM.
Reply With Quote
  #2 (permalink)  
Old 04-19-2009, 10:32 PM
Junior Member
 
Join Date: Apr 2009
Posts: 2
Default

I solved this by specifying an external IP instead of trying to manage devices over VPN.
Reply With Quote
  #3 (permalink)  
Old 04-20-2009, 08:57 AM
megaposer's Avatar
Scourge of Humanity
 
Join Date: May 2006
Location: Karlsruhe, Germany
Posts: 593
Default

Hi,

basically, tunneling should be possible regardless of whether you are using an SSL or IPSec VPN. The issue is probably that the packets from the device-agent on your remote devices are not routed into the SSL-VPN tunnel because the source IP will be out of the tunnel scope.

You can alternatively hide the ACC behind your central firewall and make it accessible to the outside world via DNAT/port-forwarding.

Regards,
Henning
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:15 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.