cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
994
Views
0
Helpful
19
Replies

SSLVPN issue

ddiep
Level 4
Level 4

Simon, let's move this thread in the discussion forum so every one can see...

Simon Slater Simon Slater  says:

Don, i'm running into an issue at work with the SSL Client.

I get when installing the virtual passage client an error.:

Cisco-SSLVPN-Tunnel Install Failed: Error in getting proxy settings.

my lan is set as a static IP and the proxy gateway in work is not blocking anything.

I have tried ALL available options for proxy settings in Firefox options, advanced, network.

No proxy

Auto-detect proxy settings for this network

use system proxy settings

manual proxy configuration

is there any known issue with ssl tunnel client and proxy's?

I have tried to setup proxy in Firefox v3.6.13 with the following settings.

No Proxy

Auto detect Proxy settings for this network

Use system proxy settings

manual proxy configuration.

none of the above have worked laterly.

I have cleared all relevant cookies/data etc and made sure the cisco virtual passage folder is deleted.

Java Console also gave me this info:

Java Plug-in 1.6.0_23
Using JRE version 1.6.0_23-b05 Java HotSpot(TM) Client VM
User home directory = C:\Documents and Settings\SlaterS2
----------------------------------------------------
c:   clear console window
f:   finalize objects on finalization queue
g:   garbage collect
h:   display this help message
l:   dump classloader list
m:   print memory usage
o:   trigger logging
q:   hide console
r:   reload policy configuration
s:   dump system and deployment properties
t:   dump thread list
v:   dump thread stack
x:   clear classloader cache
0-5: set trace level to <n>
----------------------------------------------------


OS : Windows XP
Arch : x86
Home : C:\Documents and Settings\SlaterS2
Display Name is:Cisco-SSLVPN-Tunnel
Company Name is:Cisco
Product Name is:Cisco-SSLVPN
C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\
Cisco-SSLVPN-Tunnel
getDocumentBase().getHost() : darkmoon.dyndns-ip.com
server_port : 443
getDocumentBase().getPort() : -1
Source URL : https://darkmoon.dyndns-ip.com:443/
C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\ exists : false
Created Directory : C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\
Opening connection to https://darkmoon.dyndns-ip.com:443/WindowsVPDialer.jar...
URL.openStream . . .
Resource type : text/html
Last modified on : 31-Dec-2010
File size : 96281
Copying https://darkmoon.dyndns-ip.com:443/WindowsVPDialer.jar to C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\WindowsVPDialer.jar
96281 byte(s) copied
Decompressing META-INF/
Decompressing SSLDrv.sys
Decompressing SSLDrv.cat
Decompressing XTunnel.dll
Decompressing UninstallVTPassage.exe
Decompressing SSLDrv.txt
Decompressing VirtualPassageExe.exe
DES-CBC-SHA
EasyAccess
No of route entries : 1
No of routev6 entries : 0
About to execute : C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\VirtualPassageExe.exe ; 1 darkmoon.dyndns-ip.com mO1c61dw2an98yga9cstFg==::::darkmoon5 172.16.11.20 172.16.11.25 1 443 0 0 none 0.0.0.0 0 Cisco-SSLVPN-Tunnel Cisco Cisco-SSLVPN DES-CBC-SHA EasyAccess 1 172.16.10.1 255.255.255.0 0

C:\Documents and Settings\SlaterS2\CiscoCisco-SSLVPN-Tunnel\VirtualPassageExe.exe successfully invoked

it then tried to install and failed with the proxy settings issue.

19 Replies 19

ddiep
Level 4
Level 4

Simon,

I havenot heard of any issue reported related to sslvpn area lately. I have a few questions and few requests for you to try:

- You were able to connect SSLVPN using IE before, right? Can you try w/ IE?

- Can you try to connect using different VPN type, such as quickvpn or ipsecvpn. I just want to know if this only happen w/ sslvpn.

- Can you also try w/ same scenario from different area (outside of your work network).

- Have you upgraded your fw to .30? Do you know if this problem also happen in older fw?

- Please provide me the screen shot when error occurred.

- I'll pass this info to the team for further research.

Thanks.

Don

i could try MSIE though this is a coporate laptop and msie is setup for the corporate proxy.

i have however managed to fix the issue.

Java Control Panel, Network Settings, Select Direct connection.  this seems to fool the java app not to look at proxy settings and make the tunnel work!

Regards Simon

>i have however managed to fix the issue.

>Java  Control Panel, Network Settings, Select Direct connection.  this seems  to fool the java app not to look at proxy settings and make the tunnel  work.

Interesting tip. We might need to put this in FAQ section of RV220W later on.

Thanks!

Don,

Still having issues with SSL on my Corporate laptop, ie getting proxy error messages.

On my Corporate laptop, MSIE (v8) has proxy setting in the options for my FJ domain.

Firefox or Minefield are not locked down, and have no proxy settings.  I have full internet access with these broswers.


I use FF or Minefield to connect to my router.

Now, if i am not connected to my corporate domain via cisco vpn client, I cannot connect to my router via SSL.  when i try to connect and install the SSL Tunnel software I get EM:

"Cisco-SSLVPN-Tunnel Install Failed: Error in getting proxy settings"

it would appear it is reading the MSIE config, even though MSIE is not running and I am using FF or minefield.

Workaround so far.

I connect to my corporate domain with the Cisco VPN client (MSIE not running, just the VPN Client) and then I can then connect to the SSL Tunnel via Firefox/Minefield.

I know this is somewhat of a strange one, but it appears the SSL Tunnel software is trying checking the proxy settings of MSIE even though I am using a different browser.

Simon

Regards Simon

Simon,

Give me sometime to investigate and replicate your SSLVPN issue. Kinda busy working on RV110W EFT.

Btw, expect to receive your RV110W unit soon (sometime next week)! I'll follow up w/ more info.

Regards,

-Don

Simon,

I checked again and SSLVPN seemed to be working ok for me, regardless whether or not my laptop is behind corporate vpn (ie. I'm using Cisco corporate vpn client called CSCC; what is yours?)

Although I must admit, sometime I do running into problem connecting. But when I tried a "Cache Clearing" instruction, thing started to work again. Please check out the instruction (SSLVPN_Installation-1.docx.) and let me know if it's working for you.

-Don

Cisco Sytems VPN Client Version 5.0.07.0290 though it has Fujitsu logos on the application.

the fact that i can only connect via SSL to my home router once my laptop is on the corporate VPN is odd to say the least.  without that connection i get the proxy issues.  these must be from MSIE since MSIE is locked down with proxy settings even though i am using firefox without any proxy settings in ff's setup.

Regards Simon

Simon,

I trusted that you're still having same problem if using FF (?). Please provide me w/ screen shot of pop-up error when problem occcured. I'll further investigate and check w/ development team.

Thanks.

Don

Yes Don, still the same issue.

MSIE is the default browser of the corporate laptop.

I installed FF to use on any other site that doesn't require the Corporate VPN client.

now I unchecked in MSIE the options of LAN Settings, the "Use a proxy Server for your LAN" which has the corporate Proxy settings in there.

once i unchecked this setting, I can then connect to my RV220W with Firefox/Minefield.

my point is that surely if Firefox is logged into the RV2202W as a VPN user, and you try installing the SSL Tunnel software, then MSIE and any of its settings should be ignored.  FIREFOX is the Browser in use.

but at present it appears the SSL tunnel software looks for either ALL browsers and there settings or the Default browser and not the browser in use.

i have now a workaround, but this should be addressed at the "browser" level with a fix to use the proxy/lan settings of the browser that is connected to the SSL/RV220W tunnel.

Regards Simon

Simon,

I do running into *somewhat* same problem as you described. Here is my setup:

- MSIE is enable w/ "Use a proxy server for your LAN" which point to my Cisco VPN gateway.

- FF is checked/enable w/ "Use system proxy setting"

- I can not establish sslvpn using FF any more.

Work-around: from FF, set its network setting to "No Proxy". Then I'm able to connect sslvpn afterward.

I'm *guessing* what happen is when FF is set to other than "No Proxy", it might have look for some type of system proxy which could be derived from MSIE proxy configuration, and thus subsequently failed sslvpn. You already mentioned that you've tried that before (w/ "no proxy" FF) and it did not work for you. While waiting for Dev team investigation, would you do me a favor and confirm sslvpn connection w/ "FF-NoProxy" one more time?

Yes I can confirm that no proxy is selected in Firefox/Minefield. It feels like FF and minefields proxy settings are ignored.

Regards Simon

Simon,

We could not reproduce problem that you're seeing. We're able to connect sslvpn w/ FF setting to "No Proxy" or "Auto Proxy" (and w/ IE8 proxy enable). We need your help to find rootcause. Please provide following info:

-Your PC/Laptop OS

- Your IE8, FF version

- Snapshot of your IE8, FF proxy setting (along w/ detail IP address would help).

Also if possible, see if you can check w/ reverse setting. i.e. set FF to use corporate proxy and disable IE8 proxy.

Thanks.

our PC/Laptop OS

Laptop is a Fujitsu S710, 4GB Ram, WIndows XP Pro 32 bit.

Your IE8, FF version

MSIE v8.0.6001.18702 (corporate Build)

FF - Minefield v4.0b13pre

I also noticed my

FF Proxy settings are set to NO PROXY.

MSIE are shown in images.

please note it looks also like my MSIE Setting has an Automatic Configuration Script enabled and greyed out, dont know if this has anything to do with it.

tbh I'm not that bothered now since i have a workaround. either deselect enable button on the Proxy Server setting in MSIE, ot just use my VPN Client first then logon to my router via SSL with FF.

Regards Simon

I just tried loading SSLVPN this weekend and couldn't get past the virtual adapter load.  Where are the instructions again?

Jay

Certified: CCNA (R/S, Security, Voice), CCDA, CCNP (R/S)