LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 07-06-2020, 12:23 PM   #1
zohaib09
LQ Newbie
 
Registered: Dec 2018
Posts: 4

Rep: Reputation: Disabled
Openconnect VPN Server


Hi

We have installed openconnect on Ubuntu 20.04.

Facing issue client VPN remains connected (receives ping from vpn gateway) till first http request. After first http/https/browsing request (ping start to drop forever). following error start to appear in error logs

GnuTLS error (at worker-vpn.c:795): An unexpected TLS packet was received.



Can anybody advice please?
 
Old 07-06-2020, 06:53 PM   #2
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,805

Rep: Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140
I don't use OpenConnect, but based on your comment about https I would suggest that you need to use a different port for OpenConnect....

https://www.alibabacloud.com/blog/ho...-server_595185
Quote:
The default port used by OpenConnect VPN is 443. Normally a port can only be used by one service. In case you want to use port 443 for another service such as running HTTPS websites on it, then you have to change ocserv listening port number to avoid conflicts.

You can do that by re-editing the /etc/ocserv/ocserv.conf file, then find the following lines and change 443 to the desired port number.

# TCP and UDP port number
tcp-port = 443
udp-port = 443

Also edit /lib/systemd/system/ocserv.socket file:

nano /lib/systemd/system/ocserv.socket

Then, change ListenStream 443 and ListenDatagram 443 to the same port number, then run the systemctl daemon-reload command.

After making these changes, save the file and exit, then restart the OpenConnect VPN server for the changes to take effect. You can do this by running the systemctl restart ocserv command.
 
Old 07-13-2020, 06:23 AM   #3
mcroomor
LQ Newbie
 
Registered: Jul 2020
Posts: 3

Rep: Reputation: 0
I have the same issue with [link removed].

Last edited by rtmistler; 07-14-2020 at 11:29 AM.
 
Old 07-13-2020, 08:14 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by mcroomor View Post
I have the same issue with client VPN.
And it has the same solution as suggested above. Use a different port.
 
Old 07-14-2020, 11:30 AM   #5
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,882
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
Quote:
Originally Posted by mcroomor View Post
I have the same issue with [link removed].
@mcroomor,

If you wish to advertise on the Linux Questions site, please see the links at the bottom of the page for advertising info.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
kde-networkmanagement-openconnect missing .services error techorix Slackware 1 06-25-2015 07:08 AM
Trying to compile Robby's networkmanager-openconnect from SBO fails. vdemuth Slackware 10 06-02-2013 05:52 AM
openconnect problem R3V0LV3R Slackware 1 04-06-2013 12:59 PM
OpenConnect Build Error vxrcorsa90 Linux - Software 4 09-11-2012 07:40 AM
openconnect asking for hostname R3V0LV3R Slackware 3 01-31-2012 07:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration