Forums

Richard
Richard
Offline
Resolved
0 votes
I've got ibVPN updated to the newest version. I added the computers I would like running through the VPN and selected a server.

When I start the service everything starts up except I get a warning saying: INSECURE cipher with block size less then 128 bit and while the service is running the machines I added to the list no longer connect to anything on the internet. The only thing I receive is a DNS reponse for the IP address. No routing seems to happen.

The Exact message I get (I don't think this has anything to do with my problem, but maybe I'm wrong):
Nov 7 07:45:08 george ibvpn[17109]: Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Nov 7 07:45:08 george ibvpn[17109]: WARNING: INSECURE cipher with block size less than 128 bit (64 bit). This allows attacks like SWEET32. Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Nov 7 07:45:08 george ibvpn[17109]: Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Nov 7 07:45:08 george ibvpn[17109]: Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Nov 7 07:45:08 george ibvpn[17109]: WARNING: INSECURE cipher with block size less than 128 bit (64 bit). This allows attacks like SWEET32. Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Nov 7 07:45:08 george ibvpn[17109]: Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Nov 7 07:45:08 george ibvpn[17109]: WARNING: cipher with small block size in use, reducing reneg-bytes to 64MB to mitigate SWEET32 attacks.
Nov 7 07:45:08 george ibvpn[17109]: ROUTE_GATEWAY MYROUTERIP/255.255.254.0 IFACE=MYINTERFACE HWADDR=MYHWADDRADDRESS
In ibVPN
Tuesday, November 07 2017, 01:24 PM
Share this post:
Responses (2)
  • Accepted Answer

    Tuesday, November 07 2017, 04:08 PM - #Permalink
    Resolved
    0 votes
    Hi Richard,
    Have you updated to the testing version (1.2.2)? If not, please can you do a:
    yum update app-ibvpn --enablerepo=clearos-contribs-testing
    The reply is currently minimized Show
  • Accepted Answer

    Richard
    Richard
    Offline
    Thursday, November 09 2017, 02:40 PM - #Permalink
    Resolved
    0 votes
    Yes I did update to that version. I am currently using version 1.2.2-1. I had to upgrade to fix the redirection problem.

    I actually located the problem so you can shut this down. I forgot that I had the Web Proxy Server running and had to disable that to allow ibVPN to function correctly.

    Thank you.
    The reply is currently minimized Show
Your Reply