Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Open VPN take too much time to connect

Hi, i have issue with open VPN it's taking too much time to connect from client,

here is the log :

Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Aug 30 08:19:10 2016 Attempting to establish TCP connection with [AF_INET]MyStaticip:8443 [nonblock]
Tue Aug 30 08:19:10 2016 MANAGEMENT: >STATE:1472530750,TCP_CONNECT,,,
Tue Aug 30 08:19:21 2016 TCP: connect to [AF_INET]MyStaticip:8443 failed, will try again in 5 seconds: Connection timed out (WSAETIMEDOUT)
Tue Aug 30 08:19:21 2016 SIGUSR1[soft,init_instance] received, process restarting
Tue Aug 30 08:19:21 2016 MANAGEMENT: >STATE:1472530761,RECONNECTING,init_instance,,
Tue Aug 30 08:19:21 2016 Restart pause, 5 second(s)
Tue Aug 30 08:19:26 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Aug 30 08:19:26 2016 Attempting to establish TCP connection with [AF_INET]192.168.3.1:8443 [nonblock]
Tue Aug 30 08:19:26 2016 MANAGEMENT: >STATE:1472530766,TCP_CONNECT,,,
Tue Aug 30 08:19:36 2016 TCP: connect to [AF_INET]192.168.3.1:8443 failed, will try again in 5 seconds: Connection timed out (WSAETIMEDOUT)
Tue Aug 30 08:19:36 2016 SIGUSR1[soft,init_instance] received, process restarting
Tue Aug 30 08:19:36 2016 MANAGEMENT: >STATE:1472530776,RECONNECTING,init_instance,,
Tue Aug 30 08:19:36 2016 Restart pause, 5 second(s)
Tue Aug 30 08:19:41 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Aug 30 08:19:41 2016 Attempting to establish TCP connection with [AF_INET]10.10.10.1:8443 [nonblock]
Tue Aug 30 08:19:41 2016 MANAGEMENT: >STATE:1472530781,TCP_CONNECT,,,
Tue Aug 30 08:19:51 2016 TCP: connect to [AF_INET]10.10.10.1:8443 failed, will try again in 5 seconds: Connection timed out (WSAETIMEDOUT)
Tue Aug 30 08:19:51 2016 SIGUSR1[soft,init_instance] received, process restarting
Tue Aug 30 08:19:51 2016 MANAGEMENT: >STATE:1472530791,RECONNECTING,init_instance,,
Tue Aug 30 08:19:51 2016 Restart pause, 5 second(s)
Tue Aug 30 08:19:56 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Aug 30 08:19:56 2016 Attempting to establish TCP connection with [AF_INET]10.255.0.1:8443 [nonblock]
Tue Aug 30 08:19:56 2016 MANAGEMENT: >STATE:1472530796,TCP_CONNECT,,,
Tue Aug 30 08:19:57 2016 TCP connection established with [AF_INET]10.255.0.1:8443
Tue Aug 30 08:19:57 2016 TCPv4_CLIENT link local: [undef]
Tue Aug 30 08:19:57 2016 TCPv4_CLIENT link remote: [AF_INET]10.255.0.1:8443
Tue Aug 30 08:19:57 2016 MANAGEMENT: >STATE:1472530797,WAIT,,,
Tue Aug 30 08:19:57 2016 MANAGEMENT: >STATE:1472530797,AUTH,,,
Tue Aug 30 08:19:57 2016 TLS: Initial packet from [AF_INET]10.255.0.1:8443, sid=acbf375a 0ae4856a
Tue Aug 30 08:19:57 2016 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Tue Aug 30 08:19:57 2016 VERIFY ERROR: depth=1, error=self signed certificate in certificate chain: C=GB, ST=Oxfordshire, L=Abingdon, O=Sophos, OU=OU, CN=Sophos_CA, emailAddress=support@sophos.com
Tue Aug 30 08:19:57 2016 OpenSSL: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Tue Aug 30 08:19:57 2016 TLS_ERROR: BIO read tls_read_plaintext error
Tue Aug 30 08:19:57 2016 TLS Error: TLS object -> incoming plaintext read error
Tue Aug 30 08:19:57 2016 TLS Error: TLS handshake failed
Tue Aug 30 08:19:57 2016 Fatal TLS error (check_tls_errors_co), restarting
Tue Aug 30 08:19:57 2016 SIGUSR1[soft,tls-error] received, process restarting
Tue Aug 30 08:19:57 2016 MANAGEMENT: >STATE:1472530797,RECONNECTING,tls-error,,
Tue Aug 30 08:19:57 2016 Restart pause, 5 second(s)
Tue Aug 30 08:20:02 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Aug 30 08:20:02 2016 MANAGEMENT: >STATE:1472530802,RESOLVE,,,
Tue Aug 30 08:20:02 2016 Attempting to establish TCP connection with [AF_INET]MyStaticip9:8443 [nonblock]
Tue Aug 30 08:20:02 2016 MANAGEMENT: >STATE:1472530802,TCP_CONNECT,,,
Tue Aug 30 08:20:03 2016 TCP connection established with [AF_INET]MyStaticip:8443
Tue Aug 30 08:20:03 2016 TCPv4_CLIENT link local: [undef]
Tue Aug 30 08:20:03 2016 TCPv4_CLIENT link remote: [AF_INET]MyStaticip:8443
Tue Aug 30 08:20:03 2016 MANAGEMENT: >STATE:1472530803,WAIT,,,
Tue Aug 30 08:20:03 2016 MANAGEMENT: >STATE:1472530803,AUTH,,,
Tue Aug 30 08:20:03 2016 TLS: Initial packet from [AF_INET]MyStaticip:8443, sid=3b15918a 4b3de0a9
Tue Aug 30 08:20:03 2016 VERIFY OK: depth=1, C=GB, ST=Oxfordshire, L=Abingdon, O=Sophos, OU=OU, CN=Sophos_CA, emailAddress=support@sophos.com
Tue Aug 30 08:20:03 2016 VERIFY X509NAME OK: C=GB, ST=Oxfordshire, L=Abingdon, O=Sophos, OU=OU, CN=SophosApplianceCertificate, emailAddress=support@sophos.com
Tue Aug 30 08:20:03 2016 VERIFY OK: depth=0, C=GB, ST=Oxfordshire, L=Abingdon, O=Sophos, OU=OU, CN=SophosApplianceCertificate, emailAddress=support@sophos.com
Tue Aug 30 08:20:04 2016 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Aug 30 08:20:04 2016 Data Channel Encrypt: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Aug 30 08:20:04 2016 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Aug 30 08:20:04 2016 Data Channel Decrypt: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Aug 30 08:20:04 2016 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Tue Aug 30 08:20:04 2016 [SophosApplianceCertificate] Peer Connection Initiated with [AF_INET]MyStaticip:8443
Tue Aug 30 08:20:05 2016 MANAGEMENT: >STATE:1472530805,GET_CONFIG,,,
Tue Aug 30 08:20:06 2016 SENT CONTROL [SophosApplianceCertificate]: 'PUSH_REQUEST' (status=1)
Tue Aug 30 08:20:06 2016 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.81.234.5,ping 45,ping-restart 180,route 192.168.3.0 255.255.255.0,route 192.168.0.0 255.255.255.0,topology subnet,route remote_host 255.255.255.255 net_gateway,inactive 3600 30720,ifconfig 10.81.234.6 255.255.255.0'
Tue Aug 30 08:20:06 2016 OPTIONS IMPORT: timers and/or timeouts modified
Tue Aug 30 08:20:06 2016 OPTIONS IMPORT: --ifconfig/up options modified
Tue Aug 30 08:20:06 2016 OPTIONS IMPORT: route options modified
Tue Aug 30 08:20:06 2016 OPTIONS IMPORT: route-related options modified
Tue Aug 30 08:20:06 2016 ROUTE_GATEWAY 192.168.0.1/255.255.255.0 I=14 HWADDR=f8:ca:b8:59:0e:98
Tue Aug 30 08:20:06 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Tue Aug 30 08:20:06 2016 MANAGEMENT: >STATE:1472530806,ASSIGN_IP,,10.81.234.6,
Tue Aug 30 08:20:06 2016 open_tun, tt->ipv6=0
Tue Aug 30 08:20:06 2016 TAP-WIN32 device [Ethernet 2] opened: \\.\Global\{93B61CF4-DD00-457D-A18F-FE1CB23B01BC}.tap
Tue Aug 30 08:20:06 2016 TAP-Windows Driver Version 9.21
Tue Aug 30 08:20:06 2016 Set TAP-Windows TUN subnet mode network/local/netmask = 10.81.234.0/10.81.234.6/255.255.255.0 [SUCCEEDED]
Tue Aug 30 08:20:06 2016 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.81.234.6/255.255.255.0 on interface {93B61CF4-DD00-457D-A18F-FE1CB23B01BC} [DHCP-serv: 10.81.234.254, lease-time: 31536000]
Tue Aug 30 08:20:06 2016 Successful ARP Flush on interface [13] {93B61CF4-DD00-457D-A18F-FE1CB23B01BC}
Tue Aug 30 08:20:10 2016 TEST ROUTES: 4/4 succeeded len=4 ret=1 a=0 u/d=up
Tue Aug 30 08:20:10 2016 MANAGEMENT: >STATE:1472530810,ADD_ROUTES,,,
Tue Aug 30 08:20:10 2016 C:\WINDOWS\system32\route.exe ADD MyStaticip MASK 255.255.255.255 192.168.0.1
Tue Aug 30 08:20:10 2016 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=35 and dwForwardType=4
Tue Aug 30 08:20:10 2016 Route addition via IPAPI succeeded [adaptive]
Tue Aug 30 08:20:10 2016 C:\WINDOWS\system32\route.exe ADD 192.168.3.0 MASK 255.255.255.0 10.81.234.5
Tue Aug 30 08:20:10 2016 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=35 and dwForwardType=4
Tue Aug 30 08:20:10 2016 Route addition via IPAPI succeeded [adaptive]
Tue Aug 30 08:20:10 2016 C:\WINDOWS\system32\route.exe ADD 192.168.0.0 MASK 255.255.255.0 10.81.234.5
Tue Aug 30 08:20:10 2016 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=35 and dwForwardType=4
Tue Aug 30 08:20:10 2016 Route addition via IPAPI succeeded [adaptive]
Tue Aug 30 08:20:10 2016 C:\WINDOWS\system32\route.exe ADD MyStaticip MASK 255.255.255.255 192.168.0.1
Tue Aug 30 08:20:10 2016 ROUTE: route addition failed using CreateIpForwardEntry: The object already exists. [status=5010 if_index=14]
Tue Aug 30 08:20:10 2016 Route addition via IPAPI failed [adaptive]
Tue Aug 30 08:20:10 2016 Route addition fallback to route.exe
Tue Aug 30 08:20:10 2016 env_block: add PATH=C:\WINDOWS\System32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
Tue Aug 30 08:20:10 2016 Initialization Sequence Completed
Tue Aug 30 08:20:10 2016 MANAGEMENT: >STATE:1472530810,CONNECTED,SUCCESS,10.81.234.6,MyStaticip



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

    Change the Protocol to UDP. Download a fresh configuration file after making the suggested change.

    After installing the downloaded config file, go to the file location and edit it. Look for the line that says Remote x.x.x.x (your WAN IP address). Remove all the non required Remote address, just keep the Remote x.x.x.x (Static IP). For eg:


    verb 3
    reneg-sec 0
    remote 30.30.30.1 8443

    Save the file and try to connect. This will force the SSL VPN client to directly connect on the static IP address.

    Hope that helps.

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi,

    I'm new user of Sophos firewall.

    Thanks your story I solved your same issue!

    I need also to make the remote user to browse to the internet using the Public IP address of the company.

    Can you help me, please?