Overview
An OpenVPN client fails to authenticate when connecting with a CloudConnexa connection profile. The client log contains the following error message:
AUTH: Received control message: AUTH_FAILED
Note: For information about locating client logs, see Where to Find OpenVPN Client Logs.
Cause
CloudConnexa uses a web-based authentication flow that some third-party or open-source clients (such as the Ubuntu VPN GUI) don't support natively. As a result, these clients can't complete the authentication process and return an AUTH_FAILED error.
Resolution
Use one of the following options.
Option 1: Use a supported OpenVPN client
Use an OpenVPN client that supports CloudConnexa web authentication, such as:
OpenVPN Connect for Windows, macOS, Android, or iOS (version 3.1.0 and newer).
OpenVPN 3 for Linux.
Option 2: Disable connection authentication for the User group
If your users don't need web-based authentication, you can turn off Connect Auth for the User group. Users then authenticate using only the mutual TLS certificate included in their connection profile.
Important: This change affects all users within that group.
Sign in to the CloudConnexa Administration Portal.
Navigate to Users → Groups.
Select the edit button (pencil icon) for the User group.
Set the Connect Auth setting to No.
Select Save.
Note: Users must still authenticate to the User Portal to download their connection profile.
Option 3: Use a Host Connector profile
Host Connectors use mutual TLS certificates and token-based sessions instead of web authentication. Because they don't authenticate with a username and password, they aren't affected by this issue.
For more information, see About Hosts.
Comments
0 comments
Please sign in to leave a comment.