I set up the IPSec VPN in UTM manager.
Installed Sophos IPsec client by downloading from User Portal. Downloaded ini and cert from User Portal. Imported ini and cert and pointed profile to cert. When trying to connect, get error. This is the log:
/1/2019 11:04:51 AM - System: DNSHandling=0
5/1/2019 11:04:51 AM - IPSec: Start building connection
5/1/2019 11:04:51 AM - IPSec: Connecting and Pin is not entered
5/1/2019 11:04:59 AM - System: DNSHandling=0
5/1/2019 11:04:59 AM - IPSec: Start building connection
5/1/2019 11:04:59 AM - System: ikeusesocket=0
5/1/2019 11:04:59 AM - IpsDial: connection time interface choice,LocIpa=192.168.1.62,AdapterIndex=206
5/1/2019 11:04:59 AM - Ike: Outgoing connect request MAIN mode - gateway=74.142.150.90 : bberger
5/1/2019 11:04:59 AM - Ike: ConRef=11, XMIT_MSG1_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ConRef=11, Send NAT-D vendor ID,remprt=500
5/1/2019 11:04:59 AM - Ike: ConRef=11, RECV_MSG2_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: IKE phase I: Setting LifeTime to 28800 seconds
5/1/2019 11:04:59 AM - Ike: IkeSa1 negotiated with the following properties -
5/1/2019 11:04:59 AM - Authentication=RSA_SIGNATURES,Encryption=DES3,Hash=SHA,DHGroup=14,KeyLen=0
5/1/2019 11:04:59 AM - IPSec: Final Tunnel EndPoint is=74.142.150.90
5/1/2019 11:04:59 AM - Ike: bberger ->Support for NAT-T version - 9
5/1/2019 11:04:59 AM - Ike: ConRef=11, XMIT_MSG3_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ConRef=11, RECV_MSG4_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ConRef=11, RECV_MSG4_MAIN_RESUME, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ConRef=11, XMIT_MSG5_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - ike_phase1:send_id:ID_USER_FQDN:pid=0,port=0,bberger@knoxhealth.com
5/1/2019 11:04:59 AM - Ike: ConRef=11, XMIT_MSG5_MAIN_RESUME, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ConRef=11, RECV_MSG6_MAIN, name=bberger, vpngw=74.142.150.90:500
5/1/2019 11:04:59 AM - Ike: ike_phase1:recv_id:ID_FQDN:pid=0,port=0,sophos.knoxhealth.com
5/1/2019 11:04:59 AM - ERROR - 4036: IKE(phase1)- PKI ERROR: - <bberger> Client Error: Verify Server Certificate with error 2002 ! (unable to get issuer certificate).
5/1/2019 11:04:59 AM - Ike: phase1:name(bberger) - ERROR - PKI ERROR: - <bberger> Client Error: Verify Server Certificate with error 2002 ! (unable to get issuer certificate).
5/1/2019 11:04:59 AM - IPSec: Disconnected from bberger on channel 1.
Can't find anything useful on how to resolve this error...
Thanks.
This thread was automatically locked due to age.