Jump to content

Recommended Posts

Posted
Yes I had two issues - one the service had been disabled (easy fix) and the second was routing issues due to RIP being removed from Maiden but not being documented - I had to rollback to Leeds.
  • Thanks 1
Posted

Thanks I think it was documented a long time ago that they were going to remove a couple of stuff that was basically not being used.

So how did you fix the SSL VPN issue. I also realised that when i generated a client archive the VPN installer is not apart of the zip file.

Posted
Thanks I think it was documented a long time ago that they were going to remove a couple of stuff that was basically not being used.

So how did you fix the SSL VPN issue. I also realised that when i generated a client archive the VPN installer is not apart of the zip file.

 

RIP removal wasn’t ever documented and is vital for our WAN configuration.

 

They got rid of the client as it’s meant to be a more compliant OpenVPN file Maiden produces/uses.

 

You can turn the VPN service back on in the web GUI.

  • Thanks 1
Posted

Some folks have found that their certificate is too insecure (eg MD5) for the newer version of openVPN - anything telling in the logs?

@Primus would you mind DM'ing me to identify yourself? We are gathering data on the RIP situation.

Posted

When i try to connect nothing happens nothing shows in the logs. Its like after the update connection totally blocked.

So is the smoothwall client i have installed deprecated?

Posted

On the client, uninstall everything related to the VPN.

Check that you don't have any TAP-Windows Adapter left in the device manager.

 

Then install the latest OpenVPN client with admin rights.

 

Yes, Smoothwall's own client for Windows is not updated as the Open VPN client works well and it is also available for Mac.

Posted (edited)

if ssl vpn is removed does this mean reverse proxy is broken?

 

if i turn off ssl vpn, reverse proxy dies too (leeds) so this would be a pain if it was removed all together. Id had this looked at by engineers as id idealy wanted the vpn function off as its unused but they couldnt figure it out.

Edited by DGardiner
Posted

SSL VPN is absolutely not removed in Maiden and not in the next version Newport, but it is updated to a newer version.

 

It is the client itself, the SSL client for Windows, which will not be developed further, as there are many good free alternatives such as e.g. OpenVPN.

That is when you update to Maiden, you should also update the clients to the latest version.

 

Reverse Proxy remains as before. Shouldn't have anything to do with SSL VPN, but instead of troubleshooting Leeds, update to Maiden which is also faster.

  • Thanks 1
Posted
SSL VPN is absolutely not removed in Maiden and not in the next version Newport, but it is updated to a newer version.

 

It is the client itself, the SSL client for Windows, which will not be developed further, as there are many good free alternatives such as e.g. OpenVPN.

That is when you update to Maiden, you should also update the clients to the latest version.

 

Reverse Proxy remains as before. Shouldn't have anything to do with SSL VPN, but instead of troubleshooting Leeds, update to Maiden which is also faster.

 

My smoothwall still doesnt offer maiden? i ad assumed its still on phased rlease

  • Thanks 1
Posted

I have updated my box to maiden since friday and this Update makes allot of features work faster "Internet and radius authentication to name a few but its the VPN that i cannot get to work. Openvpn asking for External Cert so it wont connect.

Only admin alone uses the vpn.

Posted

I think Smoothwall is waiting to release Maiden to everyone as it's almost soon time for Newport.

Contact support and they'll make sure you get Maiden if you have a problem with anything.

  • Thanks 1
Posted
I think Smoothwall is waiting to release Maiden to everyone as it's almost soon time for Newport.

Contact support and they'll make sure you get Maiden if you have a problem with anything.

Already have maiden running since friday.

Posted

If you use the Open VPN client, you should not install any certificate but only use the file "Connection.ovpn" which is in the zip file "SmoothWall-SSL-VPN-install" which you download from Smoothwall.

 

.ovpn contains both cert and conf. that is all that is needed.

If you use several different tunnels, you just rename Connetion to whatever you want, such as office or home..

  • Thanks 1
Posted

You have uninstalled everything and run an installation as admin and then selected "import file" where you import the file from Smoothwall...

 

Check in the client that you only have one TAP

Check that you can ping (if it is switched on in Smoothwall) the "SSL VPN client gateway" that you specified in Smoothwall

 

Are you running Windows 10 or 11?

What does it say in the client log?

  • 3 weeks later...
Posted
Some folks have found that their certificate is too insecure (eg MD5) for the newer version of openVPN - anything telling in the logs?

 

Yet to upgrade to Maiden but how would I find out if the cert is too insecure before actually starting to use the Connection.ovpn file with OpenVPN software?

 

Our VPN cert and CA have just been renewed a few days ago and works well with the Smoothwall SLL VPN client but we will be upgrading to Maiden soon.

Posted

If you have made new certificates in Maiden, there are absolutely no problems.

It's only very old certificates that can have problems from 2018 if I remember correctly...

 

If you use MacOS with SSL VPN, you must select Legacy in the OpenVPN client under settings.

Not lower security but only support for a slightly older server, this is not something that needs to be done in the PC client.OpenVPN MacOS Legacy.png

  • Thanks 1
  • 7 months later...
Posted
On 02/09/2024 at 15:28, Joeloman said:

If you use the Open VPN client, you should not install any certificate but only use the file "Connection.ovpn" which is in the zip file "SmoothWall-SSL-VPN-install" which you download from Smoothwall.

 

.ovpn contains both cert and conf. that is all that is needed.

If you use several different tunnels, you just rename Connetion to whatever you want, such as office or home..

 

What are people doing to secure the ovpn file? Is it not easy for someone to get hold of this file, leaving just username and password to connect? I thought it would have been transferred/installed in a more secure way?

Posted

Security must be considered good if you follow the usual instructions regarding Road warriors.

 

NEVER give out the SSL tunnel and certificate together with the username and password.
That is, always give these out in at least two different ways with passwords, e.g. via USB, Secure download and/or encrypted email.

 

Use Geoblocking so that only traffic from approved countries can use the tunnel.

 

In Smoothwall, a separate network is created for SSL-VPN and it is then up to you to specify which other networks and ports a user should be able to access. (Use groups)
Often, traffic is only allowed to, for example, a server that also requires a secure login or perhaps a computer/server with virtual remote desktop.

 

If you are then required to change your password with strong encryption quite often, there should not be any major security risk.

 

Many people are required to always use SSL-VPN if they are connected via WiFi, as it is quite easy to intercept wireless communication...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...