[stunnel-users] stunnel with smb from 2 networks behind firewalls

Philippe phil at migratis.net
Mon Mar 19 14:45:59 CET 2012


If I don't mention the sslVersion

here are the stunnel logs :

PCA :

2012.03.19 14:37:22 LOG5[3744:2564]: Reading configuration from file 
stunnel.conf
2012.03.19 14:37:22 LOG5[3744:2564]: FIPS mode is enabled
2012.03.19 14:37:22 LOG5[3744:2564]: Configuration successful
2012.03.19 14:37:22 LOG7[3744:2564]: Service smb bound FD=200 to 
10.232.232.232:139
2012.03.19 14:37:22 LOG7[3744:2564]: Signal pipe is empty
2012.03.19 14:37:37 LOG7[3744:2564]: Service smb accepted FD=540 from 
10.232.232.232:50020
2012.03.19 14:37:37 LOG7[3744:2564]: Creating a new thread
2012.03.19 14:37:37 LOG7[3744:2564]: New thread created
2012.03.19 14:37:37 LOG7[3744:2964]: Service smb started
2012.03.19 14:37:37 LOG5[3744:2964]: Service smb accepted connection 
from 10.232.232.232:50020
2012.03.19 14:37:37 LOG6[3744:2964]: connect_blocking: connecting 
45.212.56.178:21213
2012.03.19 14:37:37 LOG7[3744:2964]: connect_blocking: s_poll_wait 
45.212.56.178:21213: waiting 10 seconds
2012.03.19 14:37:37 LOG5[3744:2964]: connect_blocking: connected 
45.212.56.178:21213
2012.03.19 14:37:37 LOG5[3744:2964]: Service smb connected remote 
server from 192.168.3.4:50021
2012.03.19 14:37:37 LOG7[3744:2964]: Remote FD=584 initialized
2012.03.19 14:37:38 LOG3[3744:2964]: SSL_connect: 1408F10B: 
error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
2012.03.19 14:37:38 LOG5[3744:2964]: Connection reset: 0 bytes sent to 
SSL, 0 bytes sent to socket
2012.03.19 14:37:38 LOG7[3744:2964]: Service smb finished (0 left)

PCB :

2463 Mar 19 14:37:38 server stunnel: LOG5[2533:140145941337856]: 
Service smb accepted connection from 196.25.36.134:50021
2464 Mar 19 14:37:38 server stunnel: LOG3[2533:140145941337856]: 
SSL_accept: 14094410: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 
alert handshake failure
2465 Mar 19 14:37:38 server stunnel: LOG5[2533:140145941337856]: 
Connection reset: 0 bytes sent to SSL, 0 bytes sent to socket

So I'm lost ;)

Best

Philippe




More information about the stunnel-users mailing list