OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • OpenConnect Issues
« previous next »
  • Print
Pages: [1]

Author Topic: OpenConnect Issues  (Read 3329 times)

Deku

  • Newbie
  • *
  • Posts: 31
  • Karma: 4
    • View Profile
OpenConnect Issues
« on: May 28, 2019, 11:54:12 pm »
I have two OpenConnect issues.

1) The Certificate Hash will not accept my hash, but it works fine if I directly write it to the config.  The log is telling me what it wants (Server SSL certificate didn't match: pin-sha256:SD.....), but it gets reset upon reboot.  Here is the Certificate Hash (modified).
Code: [Select]
pin-sha256:SDqgu8gcbxiE487woYrZPslpdoib7+R4Xrgsj3vn8yA= (obfuscated)

2) When I do connect to the Cisco VPN, all my traffic is being routed through it, instead of just the VPN subnet.  The OpenConnect VPN is assuming the default route.  How can I fix this?  :)
« Last Edit: May 29, 2019, 12:58:00 am by Deku »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6481
  • Karma: 449
    • View Profile
Re: OpenConnect Issues
« Reply #1 on: May 29, 2019, 07:15:35 am »
1)
What is "pin-"? Is this a new option from openconnect8?
Normally you choose SHA1 or SHA256 from dropdown and only paste the hash.

2)
You have to tell your Admin to only tunnel specific networks and not all.
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Deku

  • Newbie
  • *
  • Posts: 31
  • Karma: 4
    • View Profile
Re: OpenConnect Issues
« Reply #2 on: May 29, 2019, 07:10:25 pm »
Public-Key-Pinning I think...  using sha256 with the fingerprint hash fails.  So I gave it what the log was asking for.
https://timtaubert.de/blog/2014/10/http-public-key-pinning-explained/
« Last Edit: May 29, 2019, 07:12:04 pm by Deku »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6481
  • Karma: 449
    • View Profile
Re: OpenConnect Issues
« Reply #3 on: May 29, 2019, 08:35:45 pm »
Can you connect via console when calling openconnect hostname ... Then you will see the correct hash either Sha1 or Sha256
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Deku

  • Newbie
  • *
  • Posts: 31
  • Karma: 4
    • View Profile
Re: OpenConnect Issues
« Reply #4 on: May 29, 2019, 08:43:35 pm »
Yes, when running openconnect via the console, I get this in response:
Quote
To trust this server in future, perhaps add this to your command line:
    --servercert pin-sha256:SDqgu8gcbxiE487woYrZPslpdoib7+R4Xrgsj3vn8yA=

And on the default gateway, it's doing this...
Quote
stablished DTLS connection (using OpenSSL). Ciphersuite DHE-RSA-AES256-SHA.
add host VPNSRV: gateway WANIP
add net 10.10.1.0: gateway 10.10.1.102
delete net default: gateway WANIP
add net default: gateway 10.10.1.102
« Last Edit: May 29, 2019, 09:02:00 pm by Deku »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6481
  • Karma: 449
    • View Profile
Re: OpenConnect Issues
« Reply #5 on: May 29, 2019, 09:18:24 pm »
I see, seems I have to add this feature. Can you open an issue here so I dont forget about it?
https://github.com/opnsense/plugins/issues
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • OpenConnect Issues
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2