Page 1 of 1

Errors with the apps

Posted: Wed Sep 05, 2018 8:44 am
by jpkerloch
Hi all,

Since the new update we can't connect our firewall (stormshield Pro).

With the old version of your application no issues but with the version 3.00 and 3.0.1 no connections are possible.

We have 90 users who are impacted. Please help my company.

LOG of apps:

Code: Select all

2018-09-05 08:13:19 1
2018-09-05 08:13:19 ----- OpenVPN Start -----
OpenVPN core 3.2 ios arm64 64-bit PT_PROXY built on Sep 4 2018 09:41:09
2018-09-05 08:13:19 Frame=512/2048/512 mssfix-ctrl=1250
2018-09-05 08:13:19 UNUSED OPTIONS
4 [tls-cipher] [DHE-RSA-AES256-SHA] 
6 [nobind] 
7 [resolv-retry] [infinite] 
8 [persist-key] 
9 [persist-tun] 
14 [verb] [0] 
16 [auth-retry] [interact] 

2018-09-05 08:13:19 EVENT: RESOLVE
2018-09-05 08:13:19 Contacting [X.X.X.X]:443/TCP via TCP
2018-09-05 08:13:19 EVENT: WAIT
2018-09-05 08:13:19 Connecting to [XXX.fr]:443 (X.X.X.X) via TCPv4
2018-09-05 08:13:19 EVENT: CONNECTING
2018-09-05 08:13:19 Tunnel Options:V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client
2018-09-05 08:13:19 Creds: Username/Password
2018-09-05 08:13:19 Peer Info:
IV_GUI_VER=net.openvpn.connect.ios 3.0.1-770
IV_VER=3.2
IV_PLAT=ios
IV_NCP=2
IV_TCPNL=1
IV_PROTO=2
IV_LZO=1

2018-09-05 08:13:19 TCP recv EOF
2018-09-05 08:13:19 Transport Error: Transport error on 'XXX.fr: NETWORK_EOF_ERROR
2018-09-05 08:13:19 EVENT: TRANSPORT_ERROR Transport error on 'XXX.fr: NETWORK_EOF_ERROR [ERR]
2018-09-05 08:13:19 Client terminated, restarting in 5000 ms...
2018-09-05 08:13:22 RECONNECT TEST: Internet:ReachableViaWWAN/WR t------
2018-09-05 08:13:22 EARLY RECONNECT
2018-09-05 08:13:22 Client terminated, reconnecting in 1...
2018-09-05 08:13:23 EVENT: RECONNECTING
2018-09-05 08:13:23 EVENT: RESOLVE
2018-09-05 08:13:23 Contacting [X.X.X.X]:443/TCP via TCP
2018-09-05 08:13:23 EVENT: WAIT
2018-09-05 08:13:23 Connecting to [XXX.fr]:443 (X.X.X.X) via TCPv4
2018-09-05 08:13:23 EVENT: CONNECTING
2018-09-05 08:13:23 Tunnel Options:V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client
2018-09-05 08:13:23 Creds: Username/Password
2018-09-05 08:13:23 Peer Info:
IV_GUI_VER=net.openvpn.connect.ios 3.0.1-770
IV_VER=3.2
IV_PLAT=ios
IV_NCP=2
IV_TCPNL=1
IV_PROTO=2
IV_LZO=1


2018-09-05 08:13:49 Raw stats on disconnect:
BYTES_IN : 224
BYTES_OUT : 1920
PACKETS_IN : 8
PACKETS_OUT : 16
NETWORK_EOF_ERROR : 8
TRANSPORT_ERROR : 8
CONNECTION_TIMEOUT : 1
N_RECONNECT : 7

2018-09-05 08:13:49 Performance stats on disconnect:
CPU usage (microseconds): 115818
Network bytes per CPU second: 18511
Tunnel bytes per CPU second: 0
2018-09-05 08:13:49 EVENT: DISCONNECTED
2018-09-05 08:13:49 Raw stats on disconnect:
BYTES_IN : 224
BYTES_OUT : 1920
PACKETS_IN : 8
PACKETS_OUT : 16
NETWORK_EOF_ERROR : 8
TRANSPORT_ERROR : 8
CONNECTION_TIMEOUT : 1
N_RECONNECT : 7

2018-09-05 08:13:49 Performance stats on disconnect:
CPU usage (microseconds): 117736
Network bytes per CPU second: 18210
Tunnel bytes per CPU second: 0
Thanks for your help

Re: Errors with the apps

Posted: Wed Sep 05, 2018 10:19 am
by TinCanTech
Can you post the server log at --verb 4 please.

Re: Errors with the apps

Posted: Wed Sep 05, 2018 11:13 am
by jpkerloch
Sorry, I don't find the log on the stormshield. do you knwo where I can I find it ?
I fond all others log but that.. i dont know.
Any ideas?

Re: Errors with the apps

Posted: Wed Sep 05, 2018 11:29 am
by TinCanTech
See --log & --verb in The Manual v24x

Probably specify a temporary place for the log.

Re: Errors with the apps

Posted: Thu Sep 13, 2018 2:24 pm
by talentia
Hello same problem.
Since the new update we can't connect our firewall (stormshield NG1000 ).
With the old version of your application no issues but with the version 3.00 and 3.0.1 no connections are possible.
In ou stormshiled logs, we seen authentification Ok but ssl tunnel down
It a problem with AES cipher perhaps

If you have solution from stomshield support, please post it