Hi all,

I've got a peculiar situation:
When setting up a tunnel with http encapsulation, all seems to work OK,
However, after starting a Citrix-session and a Skype4Business meeting, the 
tunnel is aborted, SEEMINGLY by the server. (note: seemingly)
I can restart the session, but with minutes (varying in time) the tunnel is 
broken again.
If I perform identical actions un an UDP-tunnel, there is never a problem, and 
my tunnel stands for hours, if not days.

Before giving specific details,  I was wondering:

1)   As Citrix is doing TCP, is it possible that TCP-in-TCP can blow the tunnel?


2)   The log on client side shows nothing peculiar, however, on server-side I 
notice "ping-exit", which is strange, as during a skype meeting data is 
continuously flowing both sides on.


3)   Much to my horror, I noticed I share this fate daily with hundreds of 
other users (but they might hardly notice it)


4)   Should I focus on the VPN-instances at either side, OR could common shared 
firewalls and reversed-proxy taken into account?
http-decapsulation is done by a single machine. Could it be that the amount of 
traffic on 443 is regarded as an attack, and hence broken down?

Met vriendelijke groet,
Hans Witvliet, J, Ing., DMO/OPS/I&S/APH, Kennis Team Opensource
Coldenhovelaan 1 Maasland 3531RC Coldehovelaan 1, kamer B213


Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u niet 
de geadresseerde bent of dit bericht abusievelijk aan u is toegezonden, wordt u 
verzocht dat aan de afzender te melden en het bericht te verwijderen. De Staat 
aanvaardt geen aansprakelijkheid voor schade, van welke aard ook, die verband 
houdt met risico's verbonden aan het elektronisch verzenden van berichten.

This message may contain information that is not intended for you. If you are 
not the addressee or if this message was sent to you by mistake, you are 
requested to inform the sender and delete the message. The State accepts no 
liability for damage of any kind resulting from the risks inherent in the 
electronic transmission of messages.
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to