Old 12-16-2011, 12:52 PM   #1 (permalink)
Untangler
 
Join Date: Nov 2010
Posts: 32
mbillings is on a distinguished road
Default OpenVPN issue in Bridge Mode

I am unable to connect to the OpenVPN server in bridge mode. I've forwarded the ports thru my ISA server and provided a static route from the range for the OpenVPN clients that points to the untangle server. I did a tracert for that range and it is routing to the Untangle server.

I'm seeing UDP 1194 traffic passing thru my firewall as well as traffic coming from the Untangle server to my client using UDP ports in the 549xx range and ISA server is passing them. However I am unable to connect and it is timing out.

I would of thought that if untangle is responding to the request I would get some sort of log on the OpenVPN application but I am not seeing anything.

Do any of you guru's have any suggestions?
mbillings is offline  
Old 12-16-2011, 04:40 PM   #2 (permalink)
Untangler
 
Join Date: Nov 2010
Posts: 32
mbillings is on a distinguished road
Default

I have gotten further now and am receiving this error.

Fri Dec 16 19:37:02 2011 TCP/UDP: Incoming packet rejected from 12.x.x.x:65073[2], expected peer address: 12.x.x.x:1194 (allow this incoming source address/port by removing --remote or adding --float)

It looks Untangle is sending a port of 65073 (which changes each time) and it is getting rejected because it is expecting port 1194.

Has anyone run across this?

Last edited by mbillings; 12-16-2011 at 04:45 PM..
mbillings is offline  
Old 12-16-2011, 06:59 PM   #3 (permalink)
Newbie
 
Steve88W's Avatar
 
Join Date: Nov 2011
Location: Southern California
Posts: 5
Steve88W is on a distinguished road
Default

Are the IP's of both networks different?
I had to change the IP scheme at home in order to connect.
Steve88W is offline  
Old 12-16-2011, 07:01 PM   #4 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,460
sky-knight is on a distinguished road
Default

The error message listed indicates a protocol issue. Meaning the UDP stream isn't connecting to Untangle.

Make sure you have your bridge plugged in the right way around. This may be a backward bridge problem.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 12-19-2011, 05:07 AM   #5 (permalink)
Untangler
 
Join Date: Nov 2010
Posts: 32
mbillings is on a distinguished road
Default

The bridge is the correct way, I see the traffic for 1194 when using the Packet test on the external interface. I have a feeling this is due to our ISA firewall siting in between untangle and the internet.

8:02:26.916486 IP 12.x.x.x.53236 > 10.100.252.249.1194: UDP, length 14
08:02:26.916996 IP 10.100.252.249.1194 > 12.x.x.x.53236: UDP, length 26

My requests are coming in however it looks as if ISA is changing the port.

Has anyone experienced this?
mbillings is offline  
Old 01-23-2012, 12:19 PM   #6 (permalink)
Newbie
 
Join Date: Jan 2012
Posts: 6
UntangleJS is on a distinguished road
Default

Was there a resolution to this? I am seeing the same behaviour with much the same setup.
Except when I connect it does work once - then if I disconnect and try to reconnect it simply does not work any longer.

If I wait an hour or so and try again it works. This happens all of the time.
UntangleJS is offline  
Old 01-23-2012, 01:06 PM   #7 (permalink)
Untangler
 
jcoffin's Avatar
 
Join Date: Aug 2008
Location: Sunnyvale, CA
URLs submitted: 1
Posts: 1,784
jcoffin is on a distinguished road
Default

Quote:
Originally Posted by UntangleJS View Post
Was there a resolution to this? I am seeing the same behaviour with much the same setup.
Except when I connect it does work once - then if I disconnect and try to reconnect it simply does not work any longer.

If I wait an hour or so and try again it works. This happens all of the time.
I would suggest starting a new thread with your details. It's almost impossible to debug your problem with no details.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
jcoffin is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:14 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2