Hallo,
ein neu eingerichteter SSL VPN Site to Site Tunnel verbindet sich nicht. XGS ist der Server, UTM ist der Client.
In den globalen SSL-VPN-Einstellungen wurden die gleichen Kryptografische Einstellungen gewählt (AES-128 CBC, SHA-1. 1024).
Die XGS meldet alle paar Sekunden "SSL VPN Site to site connection 'Zentrale_GT' established".
Im UTM LOG sieht man die Meldung "AUTH: Received control message: AUTH_FAILED".
2024:08:23-11:45:03 gate openvpn[11007]: Attempting to establish TCP connection with [AF_INET]11.22.33.44:8443 [nonblock]
2024:08:23-11:45:04 gate openvpn[11007]: TCP connection established with [AF_INET]11.22.33.44:8443 (via [AF_INET]55.66.77.88:45711)
2024:08:23-11:45:04 gate openvpn[11007]: TCPv4_CLIENT link local: [undef]
2024:08:23-11:45:04 gate openvpn[11007]: TCPv4_CLIENT link remote: [AF_INET]11.22.33.44:8443
2024:08:23-11:45:04 gate openvpn[11007]: TLS: Initial packet from [AF_INET]11.22.33.44:8443 (via [AF_INET]55.66.77.88:45711), sid=0b5b6fc7 18a49102
2024:08:23-11:45:04 gate openvpn[11007]: VERIFY OK: depth=1, C=NA, ST=NA, L=NA, O=NA, OU=NA, CN=Default_CA_5iDhUpJ6wZYOYyM, emailAddress=na@example.com
2024:08:23-11:45:04 gate openvpn[11007]: VERIFY X509NAME OK: C=NA, ST=NA, L=NA, O=NA, OU=NA, CN=Appliance_Certificate_5iDhUpJ6wZYOYyM, emailAddress=na@example.com
2024:08:23-11:45:04 gate openvpn[11007]: VERIFY OK: depth=0, C=NA, ST=NA, L=NA, O=NA, OU=NA, CN=Appliance_Certificate_5iDhUpJ6wZYOYyM, emailAddress=na@example.com
2024:08:23-11:45:05 gate openvpn[11007]: WARNING: 'cipher' is present in local config but missing in remote config, local='cipher AES-128-CBC'
2024:08:23-11:45:05 gate openvpn[11007]: Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2024:08:23-11:45:05 gate openvpn[11007]: Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2024:08:23-11:45:05 gate openvpn[11007]: Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2024:08:23-11:45:05 gate openvpn[11007]: Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2024:08:23-11:45:05 gate openvpn[11007]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
2024:08:23-11:45:05 gate openvpn[11007]: [Appliance_Certificate_5iDhUpJ6wZYOYyM] Peer Connection Initiated with [AF_INET]11.22.33.44:8443 (via [AF_INET]55.66.77.88:45711)
2024:08:23-11:45:07 gate openvpn[11007]: SENT CONTROL [Appliance_Certificate_5iDhUpJ6wZYOYyM]: 'PUSH_REQUEST' (status=1)
2024:08:23-11:45:07 gate openvpn[11007]: AUTH: Received control message: AUTH_FAILED
2024:08:23-11:45:07 gate openvpn[11007]: PLUGIN_CLOSE: /usr/lib/openvpn/plugins/openvpn-plugin-utm.so
2024:08:23-11:45:07 gate openvpn[11007]: SIGHUP[soft,auth-failure] received, process restarting
2024:08:23-11:45:07 gate openvpn[11007]: DEPRECATED OPTION: --tls-remote, please update your configuration