Unknown DTLS packets

Daniel Lenski dlenski at gmail.com
Thu Apr 12 19:28:16 PDT 2018


On Thu, Apr 12, 2018 at 5:34 AM, Charles Wise <ctwise at gmail.com> wrote:
> Hello, I'm using the latest version - OpenConnect version
> v7.08-unknown - on FreeBSD ARM.

Is that big-endian or little-endian? (Have you tested on a more
conventional system, say, Linux or BSD on arm64?)

> I have to disable DTLS (--no-dtls) or
> my VPN connection is unusable and spits out lots of unknown DTLS
> values. Is this a known issue?

Add -vvvv --dump to show the highest level of logging detail, and post
the relevant parts of the log.

> I don't know the Cisco AnyConnect
> server version but I can ask my IT support guys.

I wrote this tool which can "fingerpint" the versions of many Cisco
ASA devices, among other SSL VPN servers:
https://github.com/dlenski/what-vpn

Dan



More information about the openconnect-devel mailing list