FishCustard Posted June 3, 2013 Posted June 3, 2013 Hi guys, We've been having some problem getting our OpenVPN connection to the hosted SLG systems to work - I get a 'TLS negotiation error' or words to that effect. I believe that boils down to the fact that cannot contact the remote server (on port 1194). Capita say it's something to do with our firewall/ISP filtering - we're with LGfL 2.0, and they assure me that the relevant port is open for the appropriate source and destination IPs. My question is this: has anyone else had this problem, and what did it turn out to be? Am I on the right track with the firewall, or is there anything else I should be trying? Thanks!
IrritableTech Posted June 3, 2013 Posted June 3, 2013 We've got three things set to ensure our HSLG works... Persistent routes set upon our sims server to ensure any OpenVPN communications pass though the correct network. Proxy bypass rule setup for two addresses and ports opened on the LEA firewall. Have you got all three?
FishCustard Posted June 3, 2013 Author Posted June 3, 2013 There's no proxy config involved (LGfL proxy is transparent), the LEA say the ports are open, although I'm getting them to double-check that tomorrow. As for a persistent route, as the SIMS server is only on one network, I doubt that will change anything. However, I'm not feeling 100% today, so please correct me if I'm talking piffle. Thanks for replying, btw!
pete Posted June 4, 2013 Posted June 4, 2013 Ask LGFL if they're using packet acceleration or if they're swapped out any firewall gear recently. We had an issue last year (?) where the packet acceleration on a Checkpoint device at the LA/RBC was fragmenting the UDP keep-alives that OpenVPN uses after the initial handshaking. The symptoms for us were VPN up, twiddle thumbs, VPN down, twiddle thumbs, VPN up and so on. It turns out the device at the LA/RBC shipped with packet acceleration turned on by default.
FishCustard Posted June 5, 2013 Author Posted June 5, 2013 Working now - had to get LGfL to use 'Capita-InTouch' rule on our firewall as opposed to just allowing traffic to one destination IP.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now