FGT90D3Z15013910 # diagnose debug application sslvpn -1 Debug messages will be on for 11 minutes. FGT90D3Z15013910 # diagnose debug enable FGT90D3Z15013910 # [2535:root:356]req: /remote/portal?action=1 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667 [2535:root:357]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:357]SSL state:before SSL initialization (1.1.1.1) [2535:root:357]SSL state:before SSL initialization (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:357]SSL state:SSLv3/TLS write server done:DH lib(1.1.1.1) [2535:root:357]SSL_accept failed, 5:(null) [2535:root:357]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:358]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:358]SSL state:before SSL initialization (1.1.1.1) [2535:root:358]SSL state:before SSL initialization (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS read client key exchange (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS read change cipher spec (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS read finished (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write change cipher spec (1.1.1.1) [2535:root:358]SSL state:SSLv3/TLS write finished (1.1.1.1) [2535:root:358]SSL state:SSL negotiation finished successfully (1.1.1.1) [2535:root:358]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [2535:root:358]req: /remote/info [2535:root:358]req: /remote/login [2535:root:358]rmt_web_auth_info_parser_common:439 no session id in auth info [2535:root:358]rmt_web_get_access_cache:756 invalid cache, ret=4103 [2535:root:358]SSL state:warning close notify (1.1.1.1) [2535:root:358]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:358]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:356]req: /remote/portal?action=1 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667 [2535:root:359]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:359]SSL state:before SSL initialization (1.1.1.1) [2535:root:359]SSL state:before SSL initialization (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS read client key exchange (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS read change cipher spec (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS read finished (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write change cipher spec (1.1.1.1) [2535:root:359]SSL state:SSLv3/TLS write finished (1.1.1.1) [2535:root:359]SSL state:SSL negotiation finished successfully (1.1.1.1) [2535:root:359]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [2535:root:359]req: /remote/logincheck?&ajax=1&redir=/remote [2535:root:359]rmt_web_auth_info_parser_common:439 no session id in auth info [2535:root:359]rmt_web_access_check:682 access failed, uri=[/remote/logincheck],ret=4103, [2535:root:359]rmt_logincheck_cb_handler:900 user 'vpnuser' has a matched local entry. [2535:root:359]sslvpn_auth_check_usrgroup:1766 forming user/group list from policy. [2535:root:359]sslvpn_auth_check_usrgroup:1808 got user (1) group (0:0). [2535:root:359]sslvpn_validate_user_group_list:1436 validating with SSL VPN authentication rules (1), realm (). [2535:root:359]sslvpn_validate_user_group_list:1484 checking rule 1 cipher. [2535:root:359]sslvpn_validate_user_group_list:1492 checking rule 1 realm. [2535:root:359]sslvpn_validate_user_group_list:1503 checking rule 1 source intf. [2535:root:359]sslvpn_validate_user_group_list:1542 checking rule 1 vd source intf. [2535:root:359]sslvpn_validate_user_group_list:1614 rule 1 done, got user (1) group (0:0). [2535:root:359]sslvpn_validate_user_group_list:1702 got user (1), group (0:0). [2535:root:359]two factor check for vpnuser: off [2535:root:359]sslvpn_authenticate_user:167 authenticate user: [vpnuser] [2535:root:359]sslvpn_authenticate_user:174 create fam state [2535:root:359]fam_auth_send_req:577 with server blacklist: [2535:root:359]fam_auth_send_req_internal:449 fnbam_auth return: 0 [2535:root:359]fam_auth_send_req_internal:455 authentication OK [2535:root:359]fam_do_cb:479 fnbamd return auth success. [2535:root:359]SSL VPN login matched rule (1). [2535:root:359]rmt_web_session_create:709 create web session, idx[4] [2535:root:359]login_succeeded:383 redirect to hostcheck [2535:root:359]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:359]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:359]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:359]req: /remote/fortisslvpn [2535:root:359]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:359]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:359]SSL state:warning close notify (1.1.1.1) [2535:root:359]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:359]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:35a]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:35a]SSL state:before SSL initialization (1.1.1.1) [2535:root:35a]SSL state:before SSL initialization (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS read client key exchange (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS read change cipher spec (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS read finished (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write change cipher spec (1.1.1.1) [2535:root:35a]SSL state:SSLv3/TLS write finished (1.1.1.1) [2535:root:35a]SSL state:SSL negotiation finished successfully (1.1.1.1) [2535:root:35a]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [2535:root:35a]req: /remote/fortisslvpn_xml [2535:root:35a]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:35a]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:35a]SSL state:warning close notify (1.1.1.1) [2535:root:35a]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:35a]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:35b]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:35b]SSL state:before SSL initialization (1.1.1.1) [2535:root:35b]SSL state:before SSL initialization (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS read client key exchange (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS read change cipher spec (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS read finished (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write change cipher spec (1.1.1.1) [2535:root:35b]SSL state:SSLv3/TLS write finished (1.1.1.1) [2535:root:35b]SSL state:SSL negotiation finished successfully (1.1.1.1) [2535:root:35b]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [2535:root:35b]req: /remote/sslvpn-tunnel [2535:root:35b]sslvpn_tunnel_handler,48, Calling rmt_conn_access_ex. [2535:root:35b]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:35b]client sent request without hostname (see RFC2616 section 14.23): /. [2535:root:35b]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:35b]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:35c]allocSSLConn:280 sconn 0x311ab100 (0:root) [2535:root:35c]SSL state:before SSL initialization (1.1.1.1) [2535:root:35c]SSL state:before SSL initialization (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS read client hello (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write server hello (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write certificate (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write key exchange (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write server done:system lib(1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write server done (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS read client key exchange (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS read change cipher spec (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS read finished (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write change cipher spec (1.1.1.1) [2535:root:35c]SSL state:SSLv3/TLS write finished (1.1.1.1) [2535:root:35c]SSL state:SSL negotiation finished successfully (1.1.1.1) [2535:root:35c]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [2535:root:35c]req: /remote/logout [2535:root:35c]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:35c]session removed s: 0x311ab100 (root) [2535:root:35c]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[1.1.1.1],realm=[],idx=4,auth=1,sid=5a4534c0, login=1545014334, access=1545014334 [2535:root:0]sslvpn_internal_remove_one_web_session:2685 web session (root:vpnuser::1.1.1.1:4 1) removed for User requested termination of service [2535:root:35c]epollFdHandler,569, sconn=0x311ab100[31,-1,-1,-1,-1], fd=31, event=25. [2535:root:35c]epollFdHandler:639 s: 0x311ab100 event: 0x19 [2535:root:35c]Destroy sconn 0x311ab100, connSize=1. (root) [2535:root:356]req: /remote/portal?action=1 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667 [2535:root:356]deconstruct_session_id:378 decode session id ok, user=[vpnuser],group=[],authserver=[],portal=[tunnel-access],host=[192.168.1.110],realm=[],idx=3,auth=1,sid=3cedb07c, login=1545010667, access=1545010667