Discussion:
Cisco AnyConnect
(prestaro za odgovor)
Valentin Rosic
prije 17 godina
Permalink
pozdrav grupi,
da li netko ima kakvih iskustva sa Cisco-ovim VPN klijentom Anyconnect?
na sluzbenoj stranici pise da su testirali sa windowsima i fedorom te da
*bi trebalo* raditi na ostalim distrama.
kolegi (debian) i meni (ubuntu) se cijelo vrijeme odbija spojiti bez
obzira na instalirane requirementse (http://tinyurl.com/2cxqpa).
testirali smo i sami sa fedorom (preko vmware-a) i radi uredno.
syslog izbacuje greske, ali mi nije jasno o cemu se radi :(

molim lijepo pomoc



***@pc-kondor:/var/log$ tail -f /var/log/messages
Feb 5 08:49:05 pc-kondor -- MARK --
Feb 5 09:09:05 pc-kondor -- MARK --
Feb 5 09:29:05 pc-kondor -- MARK --
Feb 5 09:49:06 pc-kondor -- MARK --
Feb 5 10:01:47 pc-kondor logger: Stopping the VPN agent...
Feb 5 10:01:47 pc-kondor logger: Starting the VPN agent...
Feb 5 10:01:47 pc-kondor kernel: [343772.964273] tun: Universal TUN/TAP
device driver, 1.6
Feb 5 10:01:47 pc-kondor kernel: [343772.964278] tun: (C) 1999-2004 Max
Krasnyansky <***@qualcomm.com>
Feb 5 10:01:52 pc-kondor kernel: [343778.037972] cscotun0: Disabled
Privacy Extensions


***@pc-kondor:/var/log$ tail -f /var/log/syslog

Feb 5 10:33:54 pc-kondor vpn: error -
Certificates/CollectiveCertStore.cpp:790 (fe22000a)
CNSSCertStore::CNSSCertStore
Feb 5 10:33:54 pc-kondor vpn: warning -
Certificates/CollectiveCertStore.cpp:187 (fe22000a)
CCollectiveCertStore::addNSSStore
Feb 5 10:33:54 pc-kondor vpn: error -
Certificates/CollectiveCertStore.cpp:66 (fe21000e)
CCollectiveCertStore::OpenStores
Feb 5 10:33:54 pc-kondor vpn: error - Certificates/VPNCertStore.cpp:86
(fe21000e) CCapiCertStore::CCapiCertStore
Feb 5 10:33:54 pc-kondor vpn: error - Certificates/CertHelper.cpp:50
(fe21000e) CCertStoreFactory::AcquireStore
Feb 5 10:33:54 pc-kondor vpn: error - ApiCert.cpp:45 (fe21000e) CCertHelper
Feb 5 10:33:54 pc-kondor vpn: warning - SDI/SDI.cpp:52 (fe2e0001)
CRSASecurIDSDI
Feb 5 10:33:54 pc-kondor vpn: warning - SDIMgr.cpp:103 (fe2e0001)
CSDI::createInstance
Feb 5 10:33:54 pc-kondor vpn: ClientIfc.cpp:153 (0) ClientIfc :: attach
Client successfully attached.
Feb 5 10:34:23 pc-kondor monit[5471]: 'datafs' inode usage 186126
matches resource limit [inode usage>30000]
Feb 5 10:35:00 pc-kondor vpn: warning - ProfileMgr.cpp:302 (0)
ProfileMgr :: getHostInitSettings Profile settings not available for
vpn.srce.hr.
Feb 5 10:35:00 pc-kondor vpn: warning - ProfileMgr.cpp:302 (0)
ProfileMgr :: getHostInitSettings Profile settings not available for
vpn.srce.hr.
Feb 5 10:35:00 pc-kondor vpn: ConnectMgr.cpp:363 (0) ConnectMgr ::
connect Initiating connection to: vpn.srce.hr
Feb 5 10:35:00 pc-kondor vpn: error - Utility/Win/HModuleMgr.cpp:83 (0)
dlopen /usr/lib/firefox/libnss3.so: wrong ELF class: ELFCLASS64
Feb 5 10:35:00 pc-kondor vpn: error - Certificates/NSSCertUtils.cpp:749
(fe000007) CHModuleMgr::STLoadLibrary
Feb 5 10:35:00 pc-kondor vpn: error - Certificates/NSSCertUtils.cpp:204
(fe000007) CNSSCertUtils::loadLibs
Feb 5 10:35:00 pc-kondor vpn: error -
Certificates/CollectiveCertStore.cpp:790 (fe22000a)
CNSSCertStore::CNSSCertStore
Feb 5 10:35:00 pc-kondor vpn: warning -
Certificates/CollectiveCertStore.cpp:187 (fe22000a)
CCollectiveCertStore::addNSSStore
Feb 5 10:35:00 pc-kondor vpn: error -
Certificates/CollectiveCertStore.cpp:66 (fe21000e)
CCollectiveCertStore::OpenStores
Feb 5 10:35:00 pc-kondor vpn: error - Certificates/VPNCertStore.cpp:86
(fe21000e) CCapiCertStore::CCapiCertStore
Feb 5 10:35:00 pc-kondor vpn: error - Certificates/CertHelper.cpp:50
(fe21000e) CCertStoreFactory::AcquireStore
Feb 5 10:35:00 pc-kondor vpn: error - ConnectIfc.cpp:551 (fe000022)
SendRequestToPeer
Feb 5 10:35:00 pc-kondor vpn: error - ConnectMgr.cpp:449 (fe000022)
ConnectIfc::connect
Feb 5 10:35:00 pc-kondor vpn: error - ConnectMgr.cpp:586 (0) ConnectMgr
:: processIfcData Unrecognized content type (Unknown) received.
Feb 5 10:35:00 pc-kondor vpn: error - ConnectMgr.cpp:607 (0) ConnectMgr
:: processIfcData Unable to process response from vpn.srce.hr.
Feb 5 10:35:00 pc-kondor vpn: ConnectMgr.cpp:626 (0) ConnectMgr ::
processIfcData Connection attempt has failed due to server certificate
problem.


dmesg
[343772.964273] tun: Universal TUN/TAP device driver, 1.6
[343772.964278] tun: (C) 1999-2004 Max Krasnyansky <***@qualcomm.com>
[343778.037972] cscotun0: Disabled Privacy Extensions
Dinko Korunic
prije 17 godina
Permalink
Post by Valentin Rosic
pozdrav grupi,
da li netko ima kakvih iskustva sa Cisco-ovim VPN klijentom Anyconnect?
Ne treba ti to ruzno smece. Smece, jer je stvarno ocajni komad softvera, a
njihovi kernel moduli su mi vrlo cesto OOPS-ali masinu.

Odlicna zamjena za to je vpnc. It works. I koristi tun interface. Postoji
kvpnc sucelje, koje ti omogucava da Cisco pcf-ove prekonvertiras u txt
konfiguracije za vpnc.
--
NAME:Dinko.kreator.Korunic DISCLAIMER:Standard.disclaimer.applies
ICQ:16965294 JAB:***@jabber.org PGP:0xea160d0b
HOME:http://dkorunic.net QUOTE:Eat.right.stay.fit.and.die.anyway
Valentin Rosic
prije 17 godina
Permalink
Post by Dinko Korunic
Post by Valentin Rosic
pozdrav grupi,
da li netko ima kakvih iskustva sa Cisco-ovim VPN klijentom Anyconnect?
Ne treba ti to ruzno smece. Smece, jer je stvarno ocajni komad softvera, a
njihovi kernel moduli su mi vrlo cesto OOPS-ali masinu.
Odlicna zamjena za to je vpnc. It works. I koristi tun interface. Postoji
kvpnc sucelje, koje ti omogucava da Cisco pcf-ove prekonvertiras u txt
konfiguracije za vpnc.
hvala Ti na odgovoru, ali koliko vidim, ovo podržava samo IPSec, a meni
treba SSL :(



Valentin
Miroslav Zubcic
prije 17 godina
Permalink
Post by Valentin Rosic
hvala Ti na odgovoru, ali koliko vidim, ovo podržava samo IPSec, a meni
treba SSL :(
Prekopiraj negdje libssl i libcrypto sa Gedore npr. u
/opt/compat/fedoraX/lib i stavi LD_LIBRARY_PATH vpn klijentu u
environmentu da tamo traži libove. Ako treba prekopiraj i ld-linux.so.2
glibc i libm i sve čime je ova kiskova životinja dinamički linkana. Ako
ni to ne pomogne, uzmi /boot/vmlinuz-`uname -r` i /boot/initrd-`uname
-r`.img i /lib/modules/`uname -r` od Gedore i stavi na Debiana na ista
mjesta, uredi grub menu.lst i bootaj s tim kernelom. Vjerojatno će onda
raditi.
--
Copyright (c) 2007 Miroslav Zubcic, All Rights Reserved
THIS IS UNPUBLISHED PROPRIETARY OPINION OF MIROSLAV ZUBCIC
The copyright notice above does not evidence any
actual or intended publication of such opinion.
Loading...