VMware Cloud Community
vBahubali
Contributor
Contributor

SSL VPN Plus - vCloud Director 8.20 / NSX 6.2.5

Hello

I am working with vCloud director 8.20 and trying to configure  SSL VPN-Plus feature as explained in VMware Tenant Portal guide. Tenant portal guide explain  multi step configuration

Setup: vCD: 8.20, vSphere: 6.0 U2, NSX: 6.2.5

http://pubs.vmware.com/vcd-820/topic/com.vmware.ICbase/PDF/vcd_820_tenantportal.pdf

Configure SSL VPN Server Settings

Procedure

1 In the tenant portal, on the SSL VPN-Plus screen, click Server Settings.

2 Select an IPv4 address.

3 (Optional) Type a TCP port number.

This TCP port number is used by the SSL client installation package. By default, the system uses port

443, which is the default port for HTTPS/SSL traffic. Even though port number is required you can set

any TCP port for communications.

Note The SSL VPN client requires the IP address and port configured here to be reachable from your

remote users' client systems. If you change the port number from the default, ensure the IP address and

port combination will be reachable from your intended users' systems.

4 Select an encryption method in the cipher list.

5 Configure the service's syslog logging policy.

Logging is enabled by default. You can change the level of messages to log or disable logging.

6 (Optional) If you want to use a service certificate instead of the system-generated self-signed certificate

that the system uses by default, click CHANGE SERVER CERTIFICATE, make your selection, and click OK.

7 Click Save changes.

ISSUE 1: When I complete Server settings and try to save it. I get message as shown below. Now question is:

pastedImage_4.png

As per Information provided in tenant portal guide I should be able to save the setting but I cant. Is this a Normal Behavior?

As part of resolution of shown message, I discard changes (as I don’t have any other option) to move to authentication tab and get below shown message 

pastedImage_5.png

I created local authserver with default setting

pastedImage_6.png

pastedImage_7.png

ISSUE 2: When I tried to edit setting of authserver to change password policy I get below error message. Its surprising that I cant edit setting after auth server creation. Is this again a normal behaviour?

pastedImage_13.png

Below error can be seen on NSX Edge

pastedImage_14.png

ISSUE 3: I left authserver with default setting with no choice and tried creating a new user. I got below error message.  So far I am not able to configure SSL VPN- Plus feature using steps given in Tenant portal guide

pastedImage_16.png

Just to see if I can create a new user directly from NSX manager but I could not and got below error message

pastedImage_18.png

For me it seems a abnormal behaviour as i tried following documentation but i could not configure SSL VPN feature. I hope someone from VMware take a look at the sequence of steps explained in guide and issues i encountered while following it with component version provided above. Anyone encountered these problems?

Workaround I found:

I have one more VSE deployed in one of my Org vDC and for this vDC I didn’t do any other configuration for SSL VPN Plus. First step I did was to create a user and this time I didn’t encounter error. I can see a new local authserver got created and none of the setting for Authserver was found to be enabled

pastedImage_20.png

pastedImage_21.png

I tried editing auth server setting and I was able to modify setting without any error message

pastedImage_22.png

0 Kudos
1 Reply
vBahubali
Contributor
Contributor

To me this seems like a bug until unless someone is having some suggestion for me. Planning to report this internally to VMware Account Team and filling a VMware SR

0 Kudos