Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

openVPN 3.4.0 problem

Hello Dears,

I'm facing a problem with openvpn 3.4.0 (9755) on Android after the update,

My UCM is XGS2100 (SFOS 20.0.0 GA-Build222)

any help, please ??

Thank you.



This thread was automatically locked due to age.
Parents
  • Hi Jimmy Karnaby

    Please try link :  Sophos Firewall: Temporary Fix OpenVPN (3.4.0) Unsupported Options error  and keep compression turned ON and keep the 'Legacy' mode under OpenvPN under Settings > Advanced Settings > Lecagy.

    Regards

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Genuine question - Why compression ON? What is the reasoning here?

    Isn't compression OFF by default in OpenVPN (and hence, openvpn client is best suited to handle it OFF) and isn't Sophos SSL VPN OpenVPN based, in which case compression is advised against because it can be exploited by VORACLE attack?

    Even if we consider only bandwith saving measures it's not something that needs to be ON. Most traffic is not compressible since it is already compressed or it is already encrypted and can't be compressed. On small porton of thet traffic that can be compressed on vpn layer the issue is that lzo based vpn encryption is fairly inefficient since it works on one packet at a time. Higher protocol layers offer much better efficiency with compression and save more bandwith overall.

Reply
  • Genuine question - Why compression ON? What is the reasoning here?

    Isn't compression OFF by default in OpenVPN (and hence, openvpn client is best suited to handle it OFF) and isn't Sophos SSL VPN OpenVPN based, in which case compression is advised against because it can be exploited by VORACLE attack?

    Even if we consider only bandwith saving measures it's not something that needs to be ON. Most traffic is not compressible since it is already compressed or it is already encrypted and can't be compressed. On small porton of thet traffic that can be compressed on vpn layer the issue is that lzo based vpn encryption is fairly inefficient since it works on one packet at a time. Higher protocol layers offer much better efficiency with compression and save more bandwith overall.

Children