Sherlock Holmes the why the SecuExtender SSL VPN stop working
Guru Member
V1.38(ABWV.0)ITS-26WK16-m11228
But isn’t the SecuExtender SSL VPN to do with ZLD? Yes and if you think about When you have eliminated the impossible, whatever remains, however improbable, must be the truth!
So I have a Zywall 110 I test SSL VPN LAN side it works but from the internet it don't...hmm I did a packet capture and can see the connection but it was not completing it would get to Client Hello then ACK and server hello then Certificate, Server Key Exchange, Server Hello Done then stops.
Now the Zywall 110 runs through the new uOS so I have a FLEX200 that ZLD have the SSL VPN port run through that to Zywall 110 and now it works!
Accepted Solution
-
Hi @PeterUK,
Thank you for providing the information!
However, with the current information available, we are still unable to determine the root cause of the issue. To proceed with further analysis, could you please send us via PM:
- The complete packet capture files
- The configuration files from both ZLD and uOS
This will allow us to perform a more in-depth investigation and identify what may be causing the SSL VPN handshake to stop after the Server Hello Done stage.
Thank you for your cooperation. :)
Zyxel Tina
0
All Replies
-
Hi @PeterUK,
Nice detective work — and thanks for the Sherlock Holmes quote, I actually learned something new today. :)
To help us investigate further, could you share a topology diagram of how the devices are connected and send us the packet captures you took?
Zyxel Tina
0 -
I do I cut down topology that should show the issue and retest with packet capture WAN FLEX 700H and LAN to Zywall 110
0 -
Here is the packet capture
FLEX 700H WAN2
FLEX 700H VLAN443
Zywall 110 VLAN 443
Here is the topology you can load at
0 -
Hi @PeterUK,
Thank you for providing the information!
However, with the current information available, we are still unable to determine the root cause of the issue. To proceed with further analysis, could you please send us via PM:
- The complete packet capture files
- The configuration files from both ZLD and uOS
This will allow us to perform a more in-depth investigation and identify what may be causing the SSL VPN handshake to stop after the Server Hello Done stage.
Thank you for your cooperation. :)
Zyxel Tina
0 -
Unless you test it yourself with the hardware you will not determine the root cause of the issue.
I PM you the config and complete packet capture for port 5130
The issue is clear there is two way traffic the root cause is the uOS handling and inspection of SSL traffic thats in the clear that it drops the connection thinking its invalid or not secure for some reason.
Update
So just to make sure the issue happens on V1.39 I found it didn't so this is fixed Tina but there was something that stopped it from working on V1.38(ABWV.0)ITS-26WK16-m11228 and did not change anything that would of stopped it from working…I mean I could go back to V1.38(ABWV.0)ITS-26WK16-m11228 to test but I'm happy its working🙂
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Zyxel Employee


