[11999:SSLVPN:0]SND: LCP Echo_Reply id(189) len(8) [Magic_Number a9caa747] [12002:SSLVPN:2db]allocSSLConn:289 sconn 0x7f645d05f500 (10:SSLVPN) [12002:SSLVPN:2db]SSL state:before SSL initialization (*.*.*.123) [12002:SSLVPN:2db]SSL state:before SSL initialization:DH lib(*.*.*.123) [12002:SSLVPN:2db]SSL_accept failed, 5:(null) [12002:SSLVPN:2db]Destroy sconn 0x7f645d05f500, connSize=7. (SSLVPN) [11991:SSLVPN:2e0]allocSSLConn:289 sconn 0x7f645d2c2400 (10:SSLVPN) [11991:SSLVPN:2e0]SSL state:before SSL initialization (*.*.*.123) [11991:SSLVPN:2e0]SSL state:before SSL initialization (*.*.*.123) [11991:SSLVPN:2e0]got SNI server name: cnt.-us.ru realm (null) [11991:SSLVPN:2e0]client cert requirement: no [11991:SSLVPN:2e0]SSL state:SSLv3/TLS read client hello (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server hello (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write certificate (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write key exchange (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done:system lib(*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS read client key exchange (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS read change cipher spec (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS read finished (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write session ticket (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write change cipher spec (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSLv3/TLS write finished (*.*.*.123) [11991:SSLVPN:2e0]SSL state:SSL negotiation finished successfully (*.*.*.123) [11991:SSLVPN:2e0]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [11991:SSLVPN:2e0]req: /remote/info [11991:SSLVPN:2e0]req: /remote/login [11991:SSLVPN:2e0]rmt_web_auth_info_parser_common:469 no session id in auth info [11991:SSLVPN:2e0]rmt_web_get_access_cache:803 invalid cache, ret=4103 [11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) [11991:SSLVPN:2e0]get_cust_page:129 saml_info 0 [11991:SSLVPN:2e0]req: /remote/logincheck [11991:SSLVPN:2e0]rmt_web_auth_info_parser_common:469 no session id in auth info [11991:SSLVPN:2e0]rmt_web_access_check:722 access failed, uri=[/remote/logincheck],ret=4103, [11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) [11991:SSLVPN:2e0]sslvpn_auth_check_usrgroup:2166 forming user/group list from policy. [11991:SSLVPN:2e0]sslvpn_auth_check_usrgroup:2272 got user (0) group (2:0). [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1697 validating with SSL VPN authentication rules (3), realm (). [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 1 cipher. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 1 realm. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 1 source intf. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1808 checking rule 1 vd source intf. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 1 done, got user (0:0) group (1:0) peer group (0). [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 2 cipher. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 2 realm. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 2 source intf. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 2 done, got user (0:0) group (2:0) peer group (0). [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 3 cipher. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 3 realm. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 3 source intf. [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 3 done, got user (0:0) group (2:0) peer group (0). [11991:SSLVPN:2e0]sslvpn_validate_user_group_list:2082 got user (0:0), group (2:0) peer group (0). [11991:SSLVPN:2e0]two factor check for user_vpn: off [11991:SSLVPN:2e0]sslvpn_authenticate_user:191 authenticate user: [user_vpn] [11991:SSLVPN:2e0]sslvpn_authenticate_user:198 create fam state [11991:SSLVPN:2e0][fam_auth_send_req_internal:405] Groups sent to FNBAM: [11991:SSLVPN:2e0]group_desc[0].grpname = VPN-group-1 [11991:SSLVPN:2e0]group_desc[1].grpname = VPN-group-2 [11991:SSLVPN:2e0][fam_auth_send_req_internal:416] FNBAM opt = 0X421 [11991:SSLVPN:2e0]fam_auth_send_req_internal:476 fnbam_auth return: 4 [11991:SSLVPN:2e0]fam_auth_send_req:879 task finished with 4 [11991:SSLVPN:2e0][fam_auth_proc_resp:1240] Authenticated groups by FNBAM: [11991:SSLVPN:2e0]auth_rsp_data.grp_list[0] = VPN-group-2 [11991:SSLVPN:2e0]Auth successful for user user_vpn in group VPN-group-2 [11991:SSLVPN:2e0]fam_do_cb:655 fnbamd return auth success. [11991:SSLVPN:2e0]SSL VPN login matched rule (2). [11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) [11991:SSLVPN:2e0]rmt_web_session_create:825 create web session, idx[10] [11991:SSLVPN:2e0]login_succeeded:524 redirect to hostcheck [11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no [11991:SSLVPN:2e0]rmt_hcinstall_cb_handler:289 set session flag to limit check.[11991:SSLVPN:2e0]req: /remote/fortisslvpn [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=yes [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no [11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) [11991:SSLVPN:2e0]req: /remote/fortisslvpn_xml [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=yes [11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no [11991:SSLVPN:2e0]rmt_fortisslvpn_xml_cb_handler:2222 Remove old sessions. [11991:SSLVPN:0]sslvpn_internal_remove_one_web_session:2877 web session (SSLVPN:user_vpn:VPN-group-2:*.*.*.123:19 1) removed for Deleted to make way for another session [11991:SSLVPN:0]sslvpn_internal_remove_apsession_by_idx:2509 free app session, idx[10] [11991:SSLVPN:2e0]sslvpn_reserve_dynip:1146 tunnel vd[SSLVPN] ip[*.*.*.11] app session idx[10] [11991:SSLVPN:2a6]cliRead,1093, read=0, tunnel finish. [11991:SSLVPN:2a6]fsv_tunnel2_state_cleanup:1348 0x7f645d2c9c00::0x7f6451b8f000 [11991:SSLVPN:2a6]fsv_disassociate_fd_to_ipaddr:1609 deassociate *.*.*.29 from tun (ssl.SSLVPN:62) [11991:SSLVPN:2a6]session removed s: 0x7f645d2c9c00 (SSLVPN)
[11999:SSLVPN:0]SND: LCP Echo_Reply id(189) len(8) [Magic_Number a9caa747][12002:SSLVPN:2db]allocSSLConn:289 sconn 0x7f645d05f500 (10:SSLVPN)[12002:SSLVPN:2db]SSL state:before SSL initialization (*.*.*.123)[12002:SSLVPN:2db]SSL state:before SSL initialization:DH lib(*.*.*.123)[12002:SSLVPN:2db]SSL_accept failed, 5:(null)[12002:SSLVPN:2db]Destroy sconn 0x7f645d05f500, connSize=7. (SSLVPN)[11991:SSLVPN:2e0]allocSSLConn:289 sconn 0x7f645d2c2400 (10:SSLVPN)[11991:SSLVPN:2e0]SSL state:before SSL initialization (*.*.*.123)[11991:SSLVPN:2e0]SSL state:before SSL initialization (*.*.*.123)[11991:SSLVPN:2e0]got SNI server name: cnt.-us.ru realm (null)[11991:SSLVPN:2e0]client cert requirement: no[11991:SSLVPN:2e0]SSL state:SSLv3/TLS read client hello (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server hello (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write certificate (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write key exchange (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done:system lib(*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write server done (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS read client key exchange (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS read change cipher spec (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS read finished (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write session ticket (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write change cipher spec (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSLv3/TLS write finished (*.*.*.123)[11991:SSLVPN:2e0]SSL state:SSL negotiation finished successfully (*.*.*.123)[11991:SSLVPN:2e0]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384[11991:SSLVPN:2e0]req: /remote/info[11991:SSLVPN:2e0]req: /remote/login[11991:SSLVPN:2e0]rmt_web_auth_info_parser_common:469 no session id in auth info[11991:SSLVPN:2e0]rmt_web_get_access_cache:803 invalid cache, ret=4103[11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])[11991:SSLVPN:2e0]get_cust_page:129 saml_info 0[11991:SSLVPN:2e0]req: /remote/logincheck[11991:SSLVPN:2e0]rmt_web_auth_info_parser_common:469 no session id in auth info[11991:SSLVPN:2e0]rmt_web_access_check:722 access failed, uri=[/remote/logincheck],ret=4103,[11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])[11991:SSLVPN:2e0]sslvpn_auth_check_usrgroup:2166 forming user/group list from policy.[11991:SSLVPN:2e0]sslvpn_auth_check_usrgroup:2272 got user (0) group (2:0).[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1697 validating with SSL VPN authentication rules (3), realm ().[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 1 cipher.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 1 realm.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 1 source intf.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1808 checking rule 1 vd source intf.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 1 done, got user (0:0) group (1:0) peer group (0).[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 2 cipher.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 2 realm.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 2 source intf.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 2 done, got user (0:0) group (2:0) peer group (0).[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1750 checking rule 3 cipher.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1758 checking rule 3 realm.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1769 checking rule 3 source intf.[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:1923 rule 3 done, got user (0:0) group (2:0) peer group (0).[11991:SSLVPN:2e0]sslvpn_validate_user_group_list:2082 got user (0:0), group (2:0) peer group (0).[11991:SSLVPN:2e0]two factor check for user_vpn: off[11991:SSLVPN:2e0]sslvpn_authenticate_user:191 authenticate user: [user_vpn][11991:SSLVPN:2e0]sslvpn_authenticate_user:198 create fam state[11991:SSLVPN:2e0][fam_auth_send_req_internal:405] Groups sent to FNBAM:[11991:SSLVPN:2e0]group_desc[0].grpname = VPN-group-1[11991:SSLVPN:2e0]group_desc[1].grpname = VPN-group-2[11991:SSLVPN:2e0][fam_auth_send_req_internal:416] FNBAM opt = 0X421[11991:SSLVPN:2e0]fam_auth_send_req_internal:476 fnbam_auth return: 4[11991:SSLVPN:2e0]fam_auth_send_req:879 task finished with 4[11991:SSLVPN:2e0][fam_auth_proc_resp:1240] Authenticated groups by FNBAM:[11991:SSLVPN:2e0]auth_rsp_data.grp_list[0] = VPN-group-2[11991:SSLVPN:2e0]Auth successful for user user_vpn in group VPN-group-2[11991:SSLVPN:2e0]fam_do_cb:655 fnbamd return auth success.[11991:SSLVPN:2e0]SSL VPN login matched rule (2).[11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])[11991:SSLVPN:2e0]rmt_web_session_create:825 create web session, idx[10][11991:SSLVPN:2e0]login_succeeded:524 redirect to hostcheck[11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no[11991:SSLVPN:2e0]rmt_hcinstall_cb_handler:289 set session flag to limit check.[11991:SSLVPN:2e0]req: /remote/fortisslvpn[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=yes[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no[11991:SSLVPN:2e0]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])[11991:SSLVPN:2e0]req: /remote/fortisslvpn_xml[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=yes[11991:SSLVPN:2e0]deconstruct_session_id:426 decode session id ok, user=[user_vpn],group=[VPN-group-2],authserver=[--NPS-1],portal=[SSLVPN-2],host=[*.*.*.123],realm=[],idx=10,auth=2,sid=71e46cac,login=1673614050,access=1673614050,saml_logout_url=no[11991:SSLVPN:2e0]rmt_fortisslvpn_xml_cb_handler:2222 Remove old sessions.[11991:SSLVPN:0]sslvpn_internal_remove_one_web_session:2877 web session (SSLVPN:user_vpn:VPN-group-2:*.*.*.123:19 1) removed for Deleted to make way for another session[11991:SSLVPN:0]sslvpn_internal_remove_apsession_by_idx:2509 free app session, idx[10][11991:SSLVPN:2e0]sslvpn_reserve_dynip:1146 tunnel vd[SSLVPN] ip[*.*.*.11] app session idx[10][11991:SSLVPN:2a6]cliRead,1093, read=0, tunnel finish.[11991:SSLVPN:2a6]fsv_tunnel2_state_cleanup:1348 0x7f645d2c9c00::0x7f6451b8f000[11991:SSLVPN:2a6]fsv_disassociate_fd_to_ipaddr:1609 deassociate *.*.*.29 from tun (ssl.SSLVPN:62)[11991:SSLVPN:2a6]session removed s: 0x7f645d2c9c00 (SSLVPN)