This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL-VPN Assistance

I am new to VPN kindly help.

I downloaded ssl-vpn.exe package from the user portal which was already setup by someone else and when I installed it on my windows machine

( C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config ) following files exist.

  • ssl-vpn config file
  • .ca security certificate 
  • .user certificate
  • .user.key certificate.

But when I create a new user under Remote Acccess-> SSL -> New Remote Access Profile  and download the .exe package from the new user portal  I get just the ssl-vpn config file but no certificates are included. 

Automatic firewall rule is enabled. When I tried to connect I get the following error:


Wed Feb 14 12:21:16 2018 MANAGEMENT: CMD 'state on'
Wed Feb 14 12:21:16 2018 MANAGEMENT: CMD 'log all on'
Wed Feb 14 12:21:16 2018 MANAGEMENT: CMD 'hold off'
Wed Feb 14 12:21:16 2018 MANAGEMENT: CMD 'hold release'
Wed Feb 14 12:21:26 2018 MANAGEMENT: CMD 'username "Auth" "abc"'
Wed Feb 14 12:21:26 2018 MANAGEMENT: CMD 'password [...]'
Wed Feb 14 12:21:26 2018 Socket Buffers: R=[65536->65536] S=[65536->65536]
Wed Feb 14 12:21:26 2018 MANAGEMENT: >STATE:1518607286,RESOLVE,,,,,,
Wed Feb 14 12:21:28 2018 RESOLVE: Cannot resolve host address: test: No such host is known.
Wed Feb 14 12:21:28 2018 MANAGEMENT: >STATE:1518607288,RESOLVE,,,,,,
Wed Feb 14 12:21:30 2018 RESOLVE: Cannot resolve host address: test: No such host is known.
Wed Feb 14 12:21:38 2018 RESOLVE: Cannot resolve host address: test: No such host is known.
Wed Feb 14 12:21:45 2018 RESOLVE: Cannot resolve host address: test: No such host is known.
Wed Feb 14 12:21:52 2018 RESOLVE: signal received during DNS resolution attempt
Wed Feb 14 12:21:52 2018 SIGTERM[hard,init_instance] received, process exiting
Wed Feb 14 12:21:52 2018 MANAGEMENT: >STATE:1518607312,EXITING,init_instance,,,,,

What am I missing?



This thread was automatically locked due to age.
  • Hi,

     

    the log is very clear about the problem.

     

    Cannot resolve host address: test: No such host is known.

     

    I think by default the fqdn is used, at least by UTM, but you can override it. I think in the advanced settings but I'm not sure.

     

    Regards,

    Daniel 

  • Hi,

    By providing the public ip address in override hostname, I could connect to the network.

    The new version does not include extra certificates I think [;)]

    Thanks.

     

  • hello I can connect to the vpn of sophos utm via ssl vpn client
    but I have the following doubt
    How can I get someone from the internal network to see me in the local network?
    through the network environment eg
    
    if I have a shared folder on my pc and I am connected to the vpn and I want a user from within the network to see me and access my folder, what do I have to do?
  • Hi and welcome to the UTM Community!

    Do you have a firewall rule like 'Internal (Network) -> Any -> VPN Pool (SSL) : Allow'?

    Cheers - Bob
    PS The original issue above was caused by the poster failing to follow The  Zeroeth Rule in Rulz.

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • not the truth I do not have it added, also how can I allow that user or ip to see certain computers within my local network
    Thank you.
  • Newer version incorporates the certificates into the ovpn file (look in the file and you will see them).


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Is this the configuration in the firewall is it correct?
  • This is most likely NOT what you want; this gives everyone on the internet access to your VPN pool. Instead of Internet IPv4 you'll want to use Internal (Network).


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.