I have a RB433A device with RouterOS 5.11. I have been running SSTP (with RADIUS auth) successfully for a while now, everything was OK until recently, when my wife (we both have Windows 7) could not establish SSTP VPN any more. She would get the error, shown in this screenshot:
Attachment:
Capture2.PNG [ 34.66 KiB | Viewed 1480 times ]
On RB433A, the this error is shown in the debug sstp log:
Attachment:
Capture.JPG [ 68.43 KiB | Viewed 1480 times ]
For me, SSTP is established fine. 2 other remote workers also have the same problem as my wife (we all use Windows 7). The certificate is valid for another month or so. My wife and I establish VPN from the same local network over the internet to the RB433A device.
Any ideas? I Wiresharked both TCP sessions of connection establishment, however the SSL error is sent encrypted back from the server, so I can't read it. Perhaps I'll try with ssldump to see what actually is sent over by the server to the failing clients.
However, can anybody help me with the "recvd too small packet" error?
I think there is a problem with some Windows 7 update. I have the same problem on upgraded Windows 7 Ultimate, when on secondary netbook I can connect to SSTP without a problem.
I will install waiting updates one by one - and try detect which give a problem
I confirming, that source of troubles is MS Patch KB2585542.
When i uninstall this patch, Mikrotik SSTP works great.
After that, i install this patch again, and try to add registry key (HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\SendExtraRecord - 2). Well, Mikrotik SSTP vpn works again great.
Ah thanks that was driving me nuts, was trying to figure out what i'd done to my laptop to break SSTP seeing as it had worked the last time I'd used it and was working fine between routerboards.
Users browsing this forum: Bing [Bot] and 16 guests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum