Re: Unknown DTLS packets

2018-04-13 Thread Chaskiel Grundman
It's possible that this is related to the issue I reported in january (http://lists.infradead.org/pipermail/openconnect-devel/2018-January/004647.html), which involves a bug in gnutls. The bug has been fixed upstream, but debian stable and ubuntu have not taken new versions of gnutls 3.5 or 3.6 sin

Re: Openconnect - Palo Alto - Okta SSO / MFA

2018-04-13 Thread Luis l
Not sure where the instructions are for the specific commit. Currently can't find those files after a recent fetch From: Daniel Lenski Sent: Friday, April 13, 2018 2:23 AM To: Luis l Cc: David Woodhouse; openconnect-devel Subject: Re: Openconnect - Palo Alto - Okta SSO / MFA   On Wed, Apr

Re: Openconnect - Palo Alto - Okta SSO / MFA

2018-04-13 Thread Luis l
Example or I just didnt have enough coffee script_that_obtains_the_portal_userauthcookie ? cant find that and dont think thats an actual file From: Daniel Lenski Sent: Friday, April 13, 2018 2:23 AM To: Luis l Cc: David Woodhouse; openconnect-devel Subject: Re: Openconnect - Palo Alto - Okt

Re: Openconnect - Palo Alto - Okta SSO / MFA

2018-04-13 Thread Luis l
After digging around i THINK its a part of this? https://github.com/arthepsy/pan-globalprotect-okta/ I downloaded it added the totp of that moment, removed pw to prompt me instead of conf and i get the below from debug = 1. My "Guess" if this worked its to be used against the command i sent pri

Re: Unknown DTLS packets

2018-04-13 Thread Daniel Lenski
On Fri, Apr 13, 2018 at 5:39 AM, Charles Wise wrote: > I'm confused as well. But it reliably fails w/o setting the explicit > MTU in the arguments. > > What command(s) do I run to tell what MTU value is _really_ being > used? This is FreeBSD 11.1-RELEASE-p7 (pfSense firewall/router). > > BTW, I wa

Re: Unknown DTLS packets

2018-04-13 Thread Daniel Lenski
On Fri, Apr 13, 2018 at 11:13 AM, Charles Wise wrote: > It shows 1322 both with and without the '-m 1322'. And now it's > working at full speed, both with and without the '-m 1322'. I checked > the config before and after the failures and the '-m 1322' is the only > difference. > > Any ideas for a

Re: Openconnect - Palo Alto - Okta SSO / MFA

2018-04-13 Thread Daniel Lenski
On Fri, Apr 13, 2018 at 8:31 AM, Luis l wrote: > After digging around i THINK its a part of this? > > https://github.com/arthepsy/pan-globalprotect-okta/ > > I downloaded it added the totp of that moment, removed pw to prompt me > instead of conf and i get the below from debug = 1. My "Guess" if