Jump to content

AlwaysOn VPN TLS 1.3 support


Recommended Posts

After enabling TLS 1.3 and disabling all other TLS settings the Windows VPN client cannot connect to the gateway anymore.

I did set the correct ECC value(s) and Cipher-suite and enabled the "setssl parameter -defaultProfile e".

 

A modern browser is able to connect to the gateway without any issue, the vpn client however gives a "ERROR | statusCallbackFunc | 71 | SSL library internal failure"

 

Is TLS 1.3 not supported yet ?

 

Firmware used is "build-13.0-76.31_nc_64" and we are using the latest VPN client available.

Link to comment
Share on other sites

  • 5 weeks later...

Did you download the latest VPN Client from the Citrix Gateway or from the web site https://docs.citrix.com/en-us/citrix-gateway/current-release/vpn-user-config/select-gateway-plugin-for-users.html / https://www.citrix.com/downloads/citrix-gateway/plug-ins/  as it could be that your client application is old?

 

 

You may also enable logging on the plugin to see better what is the error:

 

https://docs.citrix.com/en-us/citrix-gateway/current-release/maintain-monitor/ng-maintain-ng-plugin-logging-tsk.html

Link to comment
Share on other sites

  • 11 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...