andremagreen Posted August 31, 2024 Posted August 31, 2024 Did anybody have this is after maiden upgrade where the SSL VPN stopped working. I am having such an issue can anybody assist me.
Primus Posted September 1, 2024 Posted September 1, 2024 Yes I had two issues - one the service had been disabled (easy fix) and the second was routing issues due to RIP being removed from Maiden but not being documented - I had to rollback to Leeds. 1
andremagreen Posted September 1, 2024 Author Posted September 1, 2024 Thanks I think it was documented a long time ago that they were going to remove a couple of stuff that was basically not being used. So how did you fix the SSL VPN issue. I also realised that when i generated a client archive the VPN installer is not apart of the zip file.
Primus Posted September 1, 2024 Posted September 1, 2024 Thanks I think it was documented a long time ago that they were going to remove a couple of stuff that was basically not being used. So how did you fix the SSL VPN issue. I also realised that when i generated a client archive the VPN installer is not apart of the zip file. RIP removal wasn’t ever documented and is vital for our WAN configuration. They got rid of the client as it’s meant to be a more compliant OpenVPN file Maiden produces/uses. You can turn the VPN service back on in the web GUI. 1
andremagreen Posted September 1, 2024 Author Posted September 1, 2024 I was always using it so it was always on. When i use the OpenVPN client i am not getting a connection to my smoothwall.
Joeloman Posted September 2, 2024 Posted September 2, 2024 What does the log look like in the client? If you look under VPN Control in Smoothwall, do you see the client's external IP?
tom_newton Posted September 2, 2024 Posted September 2, 2024 Some folks have found that their certificate is too insecure (eg MD5) for the newer version of openVPN - anything telling in the logs? @Primus would you mind DM'ing me to identify yourself? We are gathering data on the RIP situation.
andremagreen Posted September 2, 2024 Author Posted September 2, 2024 When i try to connect nothing happens nothing shows in the logs. Its like after the update connection totally blocked. So is the smoothwall client i have installed deprecated?
Joeloman Posted September 2, 2024 Posted September 2, 2024 On the client, uninstall everything related to the VPN. Check that you don't have any TAP-Windows Adapter left in the device manager. Then install the latest OpenVPN client with admin rights. Yes, Smoothwall's own client for Windows is not updated as the Open VPN client works well and it is also available for Mac.
tom_newton Posted September 2, 2024 Posted September 2, 2024 I would suggest trying a more modern openvpn client - now there are so many we wont be packaging one any longer
DGardiner Posted September 2, 2024 Posted September 2, 2024 (edited) if ssl vpn is removed does this mean reverse proxy is broken? if i turn off ssl vpn, reverse proxy dies too (leeds) so this would be a pain if it was removed all together. Id had this looked at by engineers as id idealy wanted the vpn function off as its unused but they couldnt figure it out. Edited September 2, 2024 by DGardiner
Joeloman Posted September 2, 2024 Posted September 2, 2024 SSL VPN is absolutely not removed in Maiden and not in the next version Newport, but it is updated to a newer version. It is the client itself, the SSL client for Windows, which will not be developed further, as there are many good free alternatives such as e.g. OpenVPN. That is when you update to Maiden, you should also update the clients to the latest version. Reverse Proxy remains as before. Shouldn't have anything to do with SSL VPN, but instead of troubleshooting Leeds, update to Maiden which is also faster. 1
DGardiner Posted September 2, 2024 Posted September 2, 2024 SSL VPN is absolutely not removed in Maiden and not in the next version Newport, but it is updated to a newer version. It is the client itself, the SSL client for Windows, which will not be developed further, as there are many good free alternatives such as e.g. OpenVPN. That is when you update to Maiden, you should also update the clients to the latest version. Reverse Proxy remains as before. Shouldn't have anything to do with SSL VPN, but instead of troubleshooting Leeds, update to Maiden which is also faster. My smoothwall still doesnt offer maiden? i ad assumed its still on phased rlease 1
andremagreen Posted September 2, 2024 Author Posted September 2, 2024 I have updated my box to maiden since friday and this Update makes allot of features work faster "Internet and radius authentication to name a few but its the VPN that i cannot get to work. Openvpn asking for External Cert so it wont connect. Only admin alone uses the vpn.
Joeloman Posted September 2, 2024 Posted September 2, 2024 I think Smoothwall is waiting to release Maiden to everyone as it's almost soon time for Newport. Contact support and they'll make sure you get Maiden if you have a problem with anything. 1
andremagreen Posted September 2, 2024 Author Posted September 2, 2024 I think Smoothwall is waiting to release Maiden to everyone as it's almost soon time for Newport. Contact support and they'll make sure you get Maiden if you have a problem with anything. Already have maiden running since friday.
Joeloman Posted September 2, 2024 Posted September 2, 2024 If you use the Open VPN client, you should not install any certificate but only use the file "Connection.ovpn" which is in the zip file "SmoothWall-SSL-VPN-install" which you download from Smoothwall. .ovpn contains both cert and conf. that is all that is needed. If you use several different tunnels, you just rename Connetion to whatever you want, such as office or home.. 1
andremagreen Posted September 2, 2024 Author Posted September 2, 2024 Anybody have a listing as to what will be fixed and added to make smoothwall more feature packed?
andremagreen Posted September 2, 2024 Author Posted September 2, 2024 Yes i added connection.ovpn and still no connection
Joeloman Posted September 2, 2024 Posted September 2, 2024 You have uninstalled everything and run an installation as admin and then selected "import file" where you import the file from Smoothwall... Check in the client that you only have one TAP Check that you can ping (if it is switched on in Smoothwall) the "SSL VPN client gateway" that you specified in Smoothwall Are you running Windows 10 or 11? What does it say in the client log?
toffee_paul Posted September 18, 2024 Posted September 18, 2024 Some folks have found that their certificate is too insecure (eg MD5) for the newer version of openVPN - anything telling in the logs? Yet to upgrade to Maiden but how would I find out if the cert is too insecure before actually starting to use the Connection.ovpn file with OpenVPN software? Our VPN cert and CA have just been renewed a few days ago and works well with the Smoothwall SLL VPN client but we will be upgrading to Maiden soon.
Joeloman Posted September 18, 2024 Posted September 18, 2024 If you have made new certificates in Maiden, there are absolutely no problems. It's only very old certificates that can have problems from 2018 if I remember correctly... If you use MacOS with SSL VPN, you must select Legacy in the OpenVPN client under settings. Not lower security but only support for a slightly older server, this is not something that needs to be done in the PC client. 1
ITGuyNW Posted May 6, 2025 Posted May 6, 2025 On 02/09/2024 at 15:28, Joeloman said: If you use the Open VPN client, you should not install any certificate but only use the file "Connection.ovpn" which is in the zip file "SmoothWall-SSL-VPN-install" which you download from Smoothwall. .ovpn contains both cert and conf. that is all that is needed. If you use several different tunnels, you just rename Connetion to whatever you want, such as office or home.. What are people doing to secure the ovpn file? Is it not easy for someone to get hold of this file, leaving just username and password to connect? I thought it would have been transferred/installed in a more secure way?
Joeloman Posted May 6, 2025 Posted May 6, 2025 Security must be considered good if you follow the usual instructions regarding Road warriors. NEVER give out the SSL tunnel and certificate together with the username and password. That is, always give these out in at least two different ways with passwords, e.g. via USB, Secure download and/or encrypted email. Use Geoblocking so that only traffic from approved countries can use the tunnel. In Smoothwall, a separate network is created for SSL-VPN and it is then up to you to specify which other networks and ports a user should be able to access. (Use groups) Often, traffic is only allowed to, for example, a server that also requires a secure login or perhaps a computer/server with virtual remote desktop. If you are then required to change your password with strong encryption quite often, there should not be any major security risk. Many people are required to always use SSL-VPN if they are connected via WiFi, as it is quite easy to intercept wireless communication...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now