This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC Remote Access .scx file invalid

I'm trying to configure an IPSEC remote access VPN.  When I download and extract the configuration archive, the .tgb file appear to be valid, but the .sck file only contains the following:

cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331.

I am using the appliance certificate for the local cert and an uploaded certificate for the remote.  The remote certificate uploaded successfully and looks fine when I select it in the IPSEC config in the firewall.

This is running on:   SFVH (SFOS 19.0.0 GA-Build317))

Any suggestions would be welcome.



This thread was automatically locked due to age.
Parents
  • Hi : Based on provided error it seems it is getting matched with a known issue NC-85383 and fixed for the same has been taken in V18.5 MR-4 and V19.0.1 MR-1. This is mostly getting observed when cert or cert chain is containing german umlaut characters and translation of same details fetching in SCX is creating a problem.

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hello,

    i have the same problem. When i try to import the .scx or .tgb file into sophos connect there comes "Connection could not be parsed". When i open the .scx file in editor i see "cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331."

    I try everything to fix these issue. ApplianceCertificate (used for local cert in ipsec vpn config) and remote certificate (localy signied from xg) has no german umlaut characters or spaces. 

Reply
  • Hello,

    i have the same problem. When i try to import the .scx or .tgb file into sophos connect there comes "Connection could not be parsed". When i open the .scx file in editor i see "cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331."

    I try everything to fix these issue. ApplianceCertificate (used for local cert in ipsec vpn config) and remote certificate (localy signied from xg) has no german umlaut characters or spaces. 

Children
No Data