Jump to content

Recommended Posts

Posted

Hi All,

 

I've been using the Smoothwall SSL VPN for years on my iPad with the OpenVPN app. Works really well.

 

I recently decided to get it set up on my home PC as well. This is just for me, not for users.

 

I downloaded the client archive, installed the client. And that is where the instructions from Smoothwall seem to stop.

 

I guessed you are supposed to import the ovpn file which I did and it said it was successful. When I click connect I get prompted for my username and password followed by a TLS error.

 

TLS Authentication is turned off.

 

Log is below. Can anyone see what I have done wrong. Am I supposed to actually import any certificates. I notice there is a PEM in the archive. Am I supposed to import that too?

 

It still works fine on the iPad.

 

 

Try to start OpenVPN connection Connection 
Thu Mar 26 11:22:10 2020 OpenVPN 2.2.2 Win32-MSVC++ [sSL] [LZO2] [PKCS11] built on Dec 15 2011
Thu Mar 26 11:22:38 2020 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page).
Thu Mar 26 11:22:38 2020 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Thu Mar 26 11:22:39 2020 LZO compression initialized
Thu Mar 26 11:22:39 2020 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ]
Thu Mar 26 11:22:39 2020 Socket Buffers: R=[65536->65536] S=[65536->65536]
Thu Mar 26 11:22:39 2020 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Thu Mar 26 11:22:39 2020 Local Options hash (VER=V4): '958c5492'
Thu Mar 26 11:22:39 2020 Expected Remote Options hash (VER=V4): '79ef4284'
Thu Mar 26 11:22:39 2020 Attempting to establish TCP connection with 80.xxx.xxx.162:443
Thu Mar 26 11:22:39 2020 TCP connection established with 80.xxx.xxx.162:443
Thu Mar 26 11:22:39 2020 TCPv4_CLIENT link local: [undef]
Thu Mar 26 11:22:39 2020 TCPv4_CLIENT link remote: 80.xxx.xxx.162:443

Thu Mar 26 11:22:39 2020 TLS: Initial packet from 80.xxx.xxx.162:443, sid=a2dde0be 9fe7d009
Thu Mar 26 11:22:39 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
ERROR: TLS error! See log for detailsThu Mar 26 11:22:39 2020 VERIFY ERROR: depth=0, error=unable to get local issuer certificate: /CN=smoothwall.xxxxxxxxxacademy.org.uk/O=The_Academy/C=GB
Thu Mar 26 11:22:39 2020 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Thu Mar 26 11:22:39 2020 TLS Error: TLS object -> incoming plaintext read error
Thu Mar 26 11:22:39 2020 TLS Error: TLS handshake failed
Thu Mar 26 11:22:39 2020 Fatal TLS error (check_tls_errors_co), restarting
Thu Mar 26 11:22:39 2020 TCP/UDP: Closing socket
Thu Mar 26 11:22:39 2020 SIGUSR1[soft,tls-error] received, process restarting
Thu Mar 26 11:22:39 2020 Restart pause, 5 second(s)
DisconnectedTimeout[Maybe your cetificates are not valid. Please check if it is revoked], restart pause will be ignored! Shuting down OpenVPN ...

 

 

Thank you very much.

Posted

Downloading the client archive from the smoothwall should bring down a zip file with 3 files in it.

* the smoothwall SSL Open VPN client

* Connection.ovpn

* servercert.pem

 

Install the Smoothwall SSL open vpn client. I just agreed to all the defaults and installed the TAP too.

 

Once installed open the Smoothwall VPN SSL application.

 

Click Import and on the bottom field click the 3 dots and browse to the connection.ovpn file that is in the downloaded archive folder. Click Import to import the file.

 

Click Connect and you should be prompted with a username and password box. The connect should go green once connected

  • Thanks 1
Posted

Unfortunately that is exactly what I’m doing but getting the error shown. Must be something wrong with the config on my Smoothwall. I’ll have another go.

 

I’ve also tried turning off the firewall on the client but no effect.

 

Thank you.

Posted
If you are not using the VPN certificates for anything other than the SSL VPN I would probably suggest deleting and recreating a CA and cert set. Then use that for the SSL VPN. Follow the recommendations in the thread in smoothwall direct support.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...