I'm trying to get a Linux VPN client to connect to a SSL VPN with a Forcepoint firewall as endpoint. Also adding the previous name "Stonesoft" or "Stonegate", as most of the resources are found on the net under these.
We have about 1k endpoints and I can honestly say this forcepoint update is the biggest nightmare I've ever come across. I cannot understand how this absolute bastard of a solution can be successfully deployed reliably. I've manufactured the package about a million different ways and even at best a reboot is needed, in many cases even when installed successfully the damn thing just refuses to work properly, displaying the proxy authentication box.
I was logging into client machines as domain user with Enterprise/Domain admin privileges and able to access a shared folder containing MSI installation packages without any problem. Though, at some point tried accessing it via \IP\share_path_to_msi_packages_folder from another non-domain PC and kept getting a login pop-up.Basically, even though one allows all domain and non-domain users/groups or 'Everyone' read/write permissions on shared folder it would still not work and prompt me for username/password thereby not allowing local client to pull down packages pointed by GPO. This is caused by anonymous access disabled by default. After enabling it and giving read/write permissions to MSI folder was then able to successfully deploy majority of packages and only synology-cloud-station-3.1.-3320.msi failed (need to look into it). I was also able to access the shared folder from any non-domain machine.
It's frustrating when you get an error after sending an email message. This topic describes what you can do if you see error code 5.6.11 in a non-delivery report (also known as an NDR, bounce message, delivery status notification, or DSN).
7c6cff6d22