01-05-2020 10:53 AM - edited 02-21-2020 09:48 AM
Hello
I am running into a wall with a problem.
On one of my Interfaces on the 5508-X I have a Router connected which is using OpenVPN. On the Cisco under Access Rules I have a simple " any any ip permit" and everything works like a charm.
I wanted to get creative and manually open ports and have done so as such;
any any tcp/udp:domain permit (for the dns to resolve the server)
any any udp:1195 permit (port of the server/auth the vpn uses)
And when I do that, it does not connect and hangs with an error of "reconnecting tls-error".
I have contacted the VPN provider and they consistently mention only me needing to use 1195 for their server and 53 for the domain. When I go back to any any ip permit it works fine.
I know this is sort of an offshoot question to actual Cisco itself but maybe I am setting the access wrong?
01-05-2020 11:04 AM
01-06-2020 04:36 PM
Hello
I clearly do not understand Packet Capture too well but I did notice it showed a great multitude of ports being used when set to default. Far too many that I want to manually open.
Prior to, I did indeed use 1194 as well.
01-05-2020 02:28 PM
OpenVPN uses UDP/1194 by default. Have you tried to open that also? And sometimes TCP is also used.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide