Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Romaryo
Explorer

VPN Client (ver 84.70 to 84.71) automatic update from Gateway - Upgrade failed...

Hello! we are trying to automatically update the client from the gateway and get an update error. maybe someone has an idea what could be the problem? before this update worked without any problems.

 

Log from Client:

[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: VerifyServerCertificate status: 800b0109
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.11 with: 1.2.840.113549.1.1.5
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.11 with: 1.2.840.113549.1.1.13
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.11 with: 1.2.840.113549.1.1.12
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.11 with: 1.2.840.113549.1.1.11
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.5 with: 1.2.840.113549.1.1.5
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.5 with: 1.2.840.113549.1.1.13
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.5 with: 1.2.840.113549.1.1.12
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: check cert alg: 1.2.840.113549.1.1.5 with: 1.2.840.113549.1.1.11
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: ROOT CA certificate hash:
[ 6596 6740][20 May 10:16:02][wssl] xxx
[ 6596 6740][20 May 10:16:02][wssl] GetServerCertificate: Server certificate hash:
[ 6596 6740][20 May 10:16:02][wssl] xxx
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Connection Info:
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: --------------
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Protocol: 0x800
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Cipher: 0x660e
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Cipher strength: 128
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Hash: 0xae06
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Hash strength: 0
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Key exchange: Ē1u„S
[ 6596 6740][20 May 10:16:02][wssl] GetConnectionInfo: Key exchange strength: 256
[ 6596 6740][20 May 10:16:02][cpwssl] cpWinSSL_fwasync_connected: free old iofuncs
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_in: 2364: rc=1, next: a813a0 with 4, req: 0r, 0w
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_in: 2364: call: a813a0 with 4
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::client_handler: state: << SSL_NEGOTIATION >> - negotiation ended and succeeded
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::getAltNames: entering..
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::getAltNames: Got Alternative Names!
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::getAltNames:Got a non-DNS altname. dwAltNameChoice = 8!
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::client_handler: server_cn = xxx VPN Certificate, server_fingerprint = XXX
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::client_handler: calling verify_gw_cb without alternative names vector
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::VerifyGatewayEv: server_cn = xxx VPN Certificate, root_ca_fp = XXX
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: Got Connected: verification_stat=800b0109, fingerprint = XXX, cn = XXX VPN Certificate
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv:retreiving siteDisplayName by ActiveSiteKey, siteDisplayName name is xxx
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: mPrimaryGwKey is 2
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: mPrimaryGwKey is 2... Entered!
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: retrieved primary gw
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] automatic_mep_topology return value true, because it is Gateway config variable. Scope: site xxx ,gw NULL ,user USER
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: using primary gw xxx
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] gw_hostname return value xxx.xxx.xxx.xxx, because it is Gateway config variable. Scope: site xxx ,gw xxx ,user USER
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv:retreived gw name, gw name is xxx.xxx.xxx.xxx
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] certificate_trust_legacy_mode return value false, because it is Default variable. Scope: site xxx, gw NULL ,user USER
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] ccc_fingerprint return value XXX, because it is Gateway config variable. Scope: site xxx ,gw NULL ,user USER
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] enable_server_alternative_names return value true, because it is Default variable. Scope: site xxx, gw NULL ,user USER
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] server_cn return value xxx VPN Certificate, because it is Gateway config variable. Scope: site xxx ,gw xxx ,user USER
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: looking up values in the certificate alternative names is enabled.
[ 6596 6740][20 May 10:16:02][FLOW] TrPrimaryConnFlow::GetFlowType: mIsPrimaryConn: 1, misUpdateSiteFlow: 0
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: Running primary connect flow.
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: certificate legacy trust mode is disabled, trying extenuating verification mode
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::CertificateSanityCheck: SUCCESS - Sanity check ok
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::IsMD5AlertNeeded: entering...
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::ExtenuatingVerification: Certificate is not verified. Continue to legacy trust mode
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: non-legacy-trust-mode did not approve nor rejected site, continue with legacy trust mode
[ 6596 6740][20 May 10:16:02][TR_CONN_MANAGER] TrConnManager::VerifyGatewayEv: Fingerprint was found in configuration, site approved
[ 6596 6740][20 May 10:16:02][] fwasync_conn_get: get max buffer size (1048576) .
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::client_handler: calling the link_established cb
[ 6596 6740][20 May 10:16:02][talkhttps] ATalkHttps::ssl_established_cb: SSL ready
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::ReadyEv: ssl tunnel was successfully connected
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::ReadyEv:Send download request if exists
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RunSend: inside
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::send_data: Entering for 134 bytes
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_pending: No input data is pending.
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_out: 2364: sent 0 of 134 bytes == 134 bytes to send
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_write: Entering... buf=2b84b80, len=134
[ 6596 6740][20 May 10:16:02][wssl] WinSSL_Encrypt: EncryptMessage returned 00000000 (SEC_E_OK)
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_write: Encrypt status = 0. in=134, hdr=13, trailer=16
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_write: 163 of 163 bytes sent
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_out: 2364: managed to send 134 of 134 bytes
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_out: 2364: call: a813a0 with 5
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::client_handler: after sending packet
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_out: 2364: rc=1, next: a813a0 with 5, req: 65536r, 0w
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_pending: No input data is pending.
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RunSend: sending the following data for file download: GET /CSHELL/TRAC.cab HTTP/1.1

User-Agent: TRAC/986102705

Host: xxx.xxx.xxx.xxx

Connection: keep-alive

Cookie: CPCVPN_SESSION_ID=

[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_in: 2364: rc=1, next: a813a0 with 5, req: 65536r, 0w
[ 6596 6740][20 May 10:16:02][cpwssl] cpSSL_fwasync_pending: No input data is pending.
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_in: 2364: got 0 of 65536 bytes == 65536 bytes required
[ 6596 6740][20 May 10:16:02][cpwssl] cpWinSSL_fwasync_read: Peer has closed connection. 0 bytes not yet decrypted.
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_mux_in: 2364: peer closed connection
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_end_conn: scheduling the end of connection 2364
[ 6596 6740][20 May 10:16:02][tevent] T_event_do_del: marking for deletion socket/type: 2364/0
[ 6596 6740][20 May 10:16:02][tevent] T_event_do_del: marking for deletion socket/type: 2364/1
[ 6596 6740][20 May 10:16:02][tevent] T_event_do_del: marking for deletion socket/type: 2364/0
[ 6596 6740][20 May 10:16:02][] T_event_do_del: failed to remove WSAsocket event
[ 6596 6740][20 May 10:16:02][tevent] T_event_do_del: marking for deletion socket/type: 2364/2
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_end_conn: closing connection 2364 (conn=2c46c58)
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_end_conn: Removing connection 2364 from proxy's connection store(conn=2c46c58)
[ 6596 6740][20 May 10:16:02][proxy_wrapper] ProxyWrapper::NotifyEndConnection (3): Starting ...
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveSingleProxyRule (1): entering... my_addr:0, my_port:2267, peer_addr:0, peer_port:0
[ 6596 6740][20 May 10:16:02][] CFirewallWrapper::RemoveSingleProxyRule (1): ntohl(my_addr),ntohs(my_port),ntohl(peer_addr),ntohs(peer_port) : <0,56072> -> <0,0>
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveSingleProxyRule (2): entering, src_ip_str=0.0.0.0, src_port=56072, dest_ip_str=0.0.0.0, dest_port=0
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveSingleProxyRule (2): rule name: _AllowProxy__0.0.0.0_0_56072
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printProxyList: entering... (proxy rules counter is: 0)
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printProxyList: done
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: enter...
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [1] : allow_enroll
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [2] : AllowIpPort_xxx.xxx.xxx.xxx_443
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [3] : AllowIpPort_xxx.xxx.xxx.xxx_4500
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [4] : AllowIpPort_xxx.xxx.xxx.xxx_80
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: done.
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveRule: szRuleName = _AllowProxy__0.0.0.0_0_56072
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveRule: done.
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::removeProxyRuleFromProxyList: entering, src_ip_str=0.0.0.0, src_port=56072, dest_ip_str=0.0.0.0, dest_port=0
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::removeProxyRuleFromProxyList: fail to find proxy rule
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: enter...
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [1] : allow_enroll
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [2] : AllowIpPort_xxx.xxx.xxx.xxx_443
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [3] : AllowIpPort_xxx.xxx.xxx.xxx_4500
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: rule [4] : AllowIpPort_xxx.xxx.xxx.xxx_80
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printAllRules: done.
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printProxyList: entering... (proxy rules counter is: 0)
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::printProxyList: done
[ 6596 6740][20 May 10:16:02][TR_FIREWALL] CFirewallWrapper::RemoveSingleProxyRule (2): rule deleted successfully (if it was found)
[ 6596 6740][20 May 10:16:02][talkssl] talkssl::end_handler: ending connection
[ 6596 6740][20 May 10:16:02][talkhttps] ATalkHttps::ssl_failure_cb: SSL ended. err=3
[ 6596 6740][20 May 10:16:02][talkhttps] ResetRcvBuffer: data 00000000 size 0 free_buffer=1.
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::EndEv: got disconnected with AuthError_t==11.
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::EndEv: connection status 0
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RetryRequest: Download Enter
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RemoveRequest: Called with cccError 399
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RemoveRequest: Calling the notify callback for the request 18
[ 6596 6740][20 May 10:16:02][UPGRADE_MANAGER] UpgradeManager::Notify: Error, got 399 errorcode
[ 6596 6740][20 May 10:16:02][TR_FLOW_STEP] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback: entering...
[ 6596 6740][20 May 10:16:02][TR_FLOW_STEP] TR_FLOW_STEP::TrUpgradeClientStep::UpgradeCompletionCallback: Upgrade failed. Set user_upgrade_mode to REMIND_USER
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] ConfigurationManager::removeParam remove 'user_upgrade_mode', source: '3'
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] ConfigurationManager::save()
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] ConfigurationManager::save()
[ 6596 6740][20 May 10:16:02][slim_utils] RaisDbSetValue: Trying to open or create registry: Software\CheckPoint\TRAC
[ 6596 6740][20 May 10:16:02][slim_utils] RaisDbSetValue: Successfully opened key Software\CheckPoint\TRAC
[ 6596 6740][20 May 10:16:02][slim_utils] RaisDbSetValue: Successfully set (DWORD) key UpgradeAskTime with value 1621498562
[ 6596 6740][20 May 10:16:02][String] String::String::Translate: String with id 9 has been translated to string: Fehler bei Client-Aktualisierung
[ 6596 6740][20 May 10:16:02][MessageLoop] MessageLoop::MessageLoop::SchedCB: entering.
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RemoveRequest: Returned callback for the request 18
[ 6596 6740][20 May 10:16:02][TalkCCC] talkccc::RetryAllRequests: exit!
[ 6596 6740][20 May 10:16:02][cpwssl] cpWinSSL_fwasync_close: closing - conn - 0x2c46c58
[ 6596 6740][20 May 10:16:02][fwasync] fwasync_do_end_conn: end closing connection 2c46c58 2364
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] ConfigurationManager::saveToFile()
[ 6596 6740][20 May 10:16:02][XmlWrapper] XmlDocument::XmlDocument: inside
[ 6596 6740][20 May 10:16:02][XmlWrapper] XmlDocument::SaveString: inside
[ 6596 6740][20 May 10:16:02][CONFIG_MANAGER] OBSCURE_FILE return value 1, because it is Default variable. Scope: site NULL, gw NULL ,user USER
[ 6596 6740][20 May 10:16:02][FLOW] TrPrimaryConnFlow::GetFlowType: mIsPrimaryConn: 1, misUpdateSiteFlow: 0

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I recommend engaging with the TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events