On 09/06/2018 10:22 AM, 22...@tutamail.com wrote:
It appears as if I am getting a TLS error? Why would this suddenly start?

Wed Sep  5 17:23:39 2018 TLS Error: TLS handshake failed
Wed Sep  5 17:23:39 2018 SIGUSR1[soft,tls-error] received, process restarting
Wed Sep  5 17:23:39 2018 Restart pause, 5 second(s)
Wed Sep  5 17:23:44 2018 TCP/UDP: Preserving recently used remote address: 
[AF_INET]xxx.xxx.xxx.xx:port xxx

I have restarted the computer, I am using Qubes 4.0 and leveraging a Debian 9 
template.

The other devices are using OpenVPN...

Any ideas?

When I search on the TLS error I get results like this:
https://serverfault.com/questions/709860/fix-tls-error-tls-handshake-failed-on-openvpn-client#765205

Specifying 'local' may be worth a try.

It sounds like something has gone wrong with the virtual devices or the Qubes firewall for that VM... perhaps triggered by the system update.

I'm also using Debian 9 on Qubes 4. dom0 is updated with security-testing enabled. Check your kernel version, mine is 4.14.67-1.

Testing basic connectivity for the VM can be done by first disabling the tunnel firewall rules... delete the link at /rw/config/qubes-firewall.d/90_tunnel-restrict. Then restart VM and use ping/traceroute.



John,
Not sure what " script in an appvm/qube  instead of the "tunnel"  version ?" is...I had 
tried to set up the "iptables and CLI scripts" https://www.qubes-os.org/doc/vpn/ but really 
struggled. I found the Tasket solution easier to set up for a relative novice in desperate need of VPN 
security. I am also able to setup a few configurations so I can use different destinations. Is this the 
version you are using?

You can think of the vpn doc as a much older version of qubes-tunnel. I doubt switching to it would help.


--

Chris Laprise, tas...@posteo.net
https://github.com/tasket
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB  4AB3 1DC4 D106 F07F 1886

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1460cb9e-f9ff-12ed-0512-9c2d964a530f%40posteo.net.
For more options, visit https://groups.google.com/d/optout.

Reply via email to