Forum Discussion
DTLS VPN doesn't work when SSL profile not default clientssl
I have inherited the settings from the clientssl profile. So all the same cyphers should be available. All of the settings are at the default. I will try adding options to say NO TLS 1.2/1.1 and see if that works.
I found some extra logs.
48,2016-02-03,13:33:41:774,HOST,1592,7040,HostCtrl information: property 27, name="tunnel_dtls", value="1". 48,2016-02-03,13:33:41:774,HOST,1592,7040,HostCtrl information: property 28, name="tunnel_port_dtls", value="4433". 0,2016-02-03,13:33:41:821,HOST,1592,7040,The following destination IP address will be used for direct(DTLS) connections: 213.xx.xx.xx 0,2016-02-03,13:33:44:264,,1432,5448,Server supports DTLS 48,2016-02-03,13:33:44:530,,1432,4724,DTLS port is specified, 4433 48,2016-02-03,13:33:44:530,,1432,4724,enter, 0x588: U_ENABLE_HTTP_CHANNEL U_ENABLE_FRAME_PACKETIZER_CHANNEL U_USE_BLOCKING_SOCKET U_ENABLE_DTLS_CHANNEL 48,2016-02-03,13:33:44:530,,1432,4724,enter 48,2016-02-03,13:33:44:546,,1432,4724,exit 48,2016-02-03,13:33:44:546,,1432,4724,OpenSSL version, OpenSSL 1.0.1p 9 Jul 2015 48,2016-02-03,13:33:44:811,,1432,4660,Setting DTLS link MTU (minimum link MTU, new link MTU value), 256, 1280 1,2016-02-03,13:33:45:430,,1432,4660,EXCEPTION caught: UDTLSChannelImpl::Open() - EXCEPTION 1,2016-02-03,13:33:45:430,,1432,4660,EXCEPTION - Name resolution failed, 5 48,2016-02-03,13:33:45:430,,1432,4660,Retry with next IP address 1,2016-02-03,13:33:45:430,,1432,4660,EXCEPTION caught: UDTLSChannelImpl::Open() - EXCEPTION 1,2016-02-03,13:33:45:430,,1432,4660,EXCEPTION - SSL_connect() failed (ssl error, sys error), SSL_ERROR_SYSCALL, 0 48,2016-02-03,13:33:45:430,,1432,4660,channel is not open
- Saravanan_M_KFeb 03, 2016EmployeeHi Chris, By any chance are you using FEC (Forward Error Correction) profile in your Connectivity Profile? If yes, then try to set it to "None" and see whether the above error goes away. You can access this settings in your connectivity profile --> Edit Connectivity Profile --> General Settings --> FEC Profile. -- Saravanan
- Chris_Brunt_192Feb 03, 2016AltostratusHi, I checked and in my connectivity profile it says. FEC Profifle (not licenced) so it was already set to None. Thanks.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com