+ Post New Thread
Results 1 to 5 of 5
MIS Systems Thread, SIMS Learning Gateway AD Provisioning - OpenVPN in Technical; Hi guys, We've been having some problem getting our OpenVPN connection to the hosted SLG systems to work - I ...
  1. #1
    FishCustard's Avatar
    Join Date
    Feb 2013
    Location
    Croydon
    Posts
    420
    Thank Post
    72
    Thanked 40 Times in 36 Posts
    Rep Power
    17

    SIMS Learning Gateway AD Provisioning - OpenVPN

    Hi guys,

    We've been having some problem getting our OpenVPN connection to the hosted SLG systems to work - I get a 'TLS negotiation error' or words to that effect. I believe that boils down to the fact that cannot contact the remote server (on port 1194).

    Capita say it's something to do with our firewall/ISP filtering - we're with LGfL 2.0, and they assure me that the relevant port is open for the appropriate source and destination IPs.

    My question is this: has anyone else had this problem, and what did it turn out to be? Am I on the right track with the firewall, or is there anything else I should be trying?

    Thanks!

  2. #2
    IrritableTech's Avatar
    Join Date
    Nov 2007
    Location
    West Yorkshire
    Posts
    795
    Thank Post
    84
    Thanked 172 Times in 141 Posts
    Rep Power
    64
    We've got three things set to ensure our HSLG works...

    Persistent routes set upon our sims server to ensure any OpenVPN communications pass though the correct network. Proxy bypass rule setup for two addresses and ports opened on the LEA firewall.

    Have you got all three?

  3. #3
    FishCustard's Avatar
    Join Date
    Feb 2013
    Location
    Croydon
    Posts
    420
    Thank Post
    72
    Thanked 40 Times in 36 Posts
    Rep Power
    17
    There's no proxy config involved (LGfL proxy is transparent), the LEA say the ports are open, although I'm getting them to double-check that tomorrow. As for a persistent route, as the SIMS server is only on one network, I doubt that will change anything. However, I'm not feeling 100% today, so please correct me if I'm talking piffle.

    Thanks for replying, btw!

  4. #4


    Join Date
    Dec 2005
    Location
    In the server room, with the lead pipe.
    Posts
    4,630
    Thank Post
    275
    Thanked 777 Times in 604 Posts
    Rep Power
    223
    Ask LGFL if they're using packet acceleration or if they're swapped out any firewall gear recently. We had an issue last year (?) where the packet acceleration on a Checkpoint device at the LA/RBC was fragmenting the UDP keep-alives that OpenVPN uses after the initial handshaking.

    The symptoms for us were VPN up, twiddle thumbs, VPN down, twiddle thumbs, VPN up and so on. It turns out the device at the LA/RBC shipped with packet acceleration turned on by default.

  5. #5
    FishCustard's Avatar
    Join Date
    Feb 2013
    Location
    Croydon
    Posts
    420
    Thank Post
    72
    Thanked 40 Times in 36 Posts
    Rep Power
    17
    Working now - had to get LGfL to use 'Capita-InTouch' rule on our firewall as opposed to just allowing traffic to one destination IP.

SHARE:
+ Post New Thread

Similar Threads

  1. [SIMS] SIMS Learning gateway (attendance registers) and iPads
    By Oops_my_bad in forum MIS Systems
    Replies: 21
    Last Post: 6th January 2014, 08:30 PM
  2. [SIMS] SIMS Learning Gateway - Provisioning Users query
    By le4ne in forum MIS Systems
    Replies: 7
    Last Post: 24th November 2011, 06:07 PM
  3. [SIMS] RECALL of SIMS Learning Gateway SLG Autumn 2010
    By vikpaw in forum MIS Systems
    Replies: 24
    Last Post: 2nd February 2011, 04:15 PM
  4. [SIMS] SIMS Learning Gateway - Behavioiur Achievement element
    By ctbjs in forum MIS Systems
    Replies: 0
    Last Post: 24th January 2011, 10:44 AM
  5. sims learning gateway ad takeover?
    By browolf in forum MIS Systems
    Replies: 22
    Last Post: 26th November 2008, 06:11 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •