openconnect / openconnect-gui

MOVED TO https://gitlab.com/openconnect/openconnect-gui
https://gitlab.com/openconnect/openconnect-gui
GNU General Public License v2.0
1.3k stars 240 forks source link

DTLS establishes only on 2nd attempt #56

Open ghost opened 9 years ago

ghost commented 9 years ago

Using openconnect gui v1.3 on windows 7 64bit. connecting to cisco asa 5505 vpn server. on first attempted connect, DTLS fails to establish. I then immediately reconnect. DTLS then successfully establishes.

log here: http://fpaste.org/273720/17312144/

The behavior is consistent, happens every time.

When I connect using openconnect on ubuntu, no such problem occurs, DTLS works on first try.

nmav commented 9 years ago

Have you tried the command line openconnect.exe client? Is there some difference in output there?

ghost commented 9 years ago

The command line openconnect.exe client establishes DTLS on first try, consistently.

here is log: http://fpaste.org/275441/52245144/

TheAndyMac commented 9 years ago

Have exactly the same problem on my laptop. Works with command line, fails (at least first attempt) from GUI.

nmav commented 9 years ago

One more question, is the command line the command line included in openconnect-gui or another one? If it's the latter, could you try with the included one?

TheAndyMac commented 9 years ago

For me I was using the command line included with openconnect-gui.

nmav commented 9 years ago

Couldn't immediately figure the issue. I suspect that may be a timing issue. There will be some changes in the TUN device allocation and DTLS setup in newer libopenconnect which should address the issue.

nmav commented 9 years ago

E.g., https://github.com/nmav/openconnect-mine/commit/19379c7c1545788186e02815b9bb7a0d7cf0eda3

ghost commented 9 years ago

To confirm, yes the command line is the command line included in openconnect-gui.

Glad to hear there will be some changes that should fix this.

horar commented 8 years ago

Hi, it's really long time, may be can someone re-test with 1.4.0 and update status. Thanks in advance...

TheAndyMac commented 8 years ago

Not 100% sure, as our company VPN service will sometimes connect with DTLS and sometimes doesn't (and have no idea what causes this), but it looks to me like this specific issue has been resolved. Not sure if I should mark as complete without someone else testing on a different VPN configuration to confirm.

RinCat commented 8 years ago

This issue seems still exist in 1.4.1.

horar commented 7 years ago

ok, can we have actual logs? (original logs was from old version and not available anymore) It could be good to see openconnect and openconnect-gui logs. Thanks.

RinCat commented 7 years ago

log here https://gist.github.com/RinCat/2edfe5336bdb34b432240b0d49c46e70

horar commented 7 years ago

thanks for update; is this problem reproducible with bundled openconnect console tool? If yes, we should move this discussion to upsteram project (openconnect) mailing list and ask author

TheAndyMac commented 7 years ago

Tried with latest build and the DTLS issue seems to be fixed, or at least more reliable – both on the GUI and the command line; however, changes in our configuration on the Cisco end (around split tunnelling) mean I now have problems browsing the corporate sites and connection using Skype for Business/Lync, so I tend to use the Cisco client (which is now much more reliable on connections through FTTC broadband) for most of my work, with OpenConnect as a backup for sites/times I need specific capabilities.

Also, is there a way to (or can it be looked at adding to the backlog) to have access to all of the switches, for example: -d,--deflate | -D,--no-deflate | --compression=MODE --force-dpd=INTERVAL --http-auth=METHODS -P,--proxy=PROXYURL | --proxy-auth=METHODS -m,--mtu=MTU | --base-mtu=MTU --disable-ipv6 --pfs --no-http-keepalive --no-dtls (although assume this is Disable UDP – but should show this on the GUI)

Regards Sent from Mailhttps://go.microsoft.com/fwlink/?LinkId=550986 for Windows 10

From: Ľubomír Carikmailto:notifications@github.com Sent: 11 April 2017 23:05 To: openconnect/openconnect-guimailto:openconnect-gui@noreply.github.com Cc: TheAndyMacmailto:andrew@macaulay.me.uk; Commentmailto:comment@noreply.github.com Subject: Re: [openconnect/openconnect-gui] DTLS establishes only on 2nd attempt (#56)

thanks for update; is this problem reproducible with bundled openconnect console tool? If yes, we should move this discussion to upsteram project (openconnect) mailing list and ask author

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/openconnect/openconnect-gui/issues/56#issuecomment-293414289, or mute the threadhttps://github.com/notifications/unsubscribe-auth/AMMQxnhhfiFHjZBqUzZ17Xl4bzE2mqHYks5ru_kugaJpZM4GHaU0.

someguy233 commented 7 years ago

Im still having this problem. OpenConnect GUI version 1.5.1. Sometimes DTLS works, sometimes doesnt. When DTLS fails, the log says: Error setting up DTLS