EX SSL-VPN: Automatic Software Updating for Connect Tunnel Windows Client Not Working Properly
03/26/2020 6 People found this article helpful 485,798 Views
Description
EX SSL-VPN: Automatic Software Updating for Connect Tunnel Windows Client Not Working Properly
Resolution
Overview
In versions 8.9.0 and 9.0.0 of the SonicWall / Aventail EX-Series software the automatic software updating feature for the Windows version of the Connect Tunnel client does not always work properly.
The automatic updating feature normally enables you to ensure that your users have the most recent version of the client. Each time a user starts the Windows Connect Tunnel client and authenticates, the current client software version is checked against the newest version available on the appliance. If a newer version is available, the user is alerted that an update is ready for download. Versions 8.9.0 and 9.0.0 of the Connect Tunnel client for Windows, however, do not always alert users of a new version when the appliance is updated with new firmware or a hotfix.
Users affected by this problem may be able to connect correctly with the proper policy, but over time their client and appliance versions will be out of sync, which will prevent them from taking advantage of new features and product fixes.
This client fix consists of a simple executable script named KB4644-regfix.exe that should be run on each client machine running Connect Tunnel for Windows. The script needs to be run only once, and it should be run before you apply any additional client hotfixes recommended for v8.9.0 or v9.0.0.
In addition, a hotfix is available for the Aventail appliance which fixes the underlying problem in the Connect Tunnel client and prevents it from occurring in the future. KB4644-regfix.exe must be deployed to client systems first, however. After that executable has been run on client systems, the installed clt-hotfix should take effect for these systems and they will be prompted to install a new version of Connect Tunnel.
Resolution or Workaround
The safest course of action to resolve this issue is to:
- Deploy KB4644-regfix.exe to client systems using one of the two methods listed below.
- Install the latest version of clt-hotfix-8_9_x or clt-hotfix-9_0_x onto the Aventail appliance. It contains the latest version of Connect Tunnel.
- clt-hotfix-8_9_x is available for download from KB item #2988.
- clt-hotfix-9_0_x is available for download from KB item #4488.
Deployment of KB4644-regfix.exe can be performed in one of two ways...
- As a post-connection script (specified in AMC)
- As part of the Connect Tunnel installation (specified in a batch file)
Post-connection script
To add the script in AMC so that it runs automatically when users connect to the appliance:
1. Download the executable from here and copy it to a fileshare to which your Connect Tunnel users have access.
2. In AMC, go to the Network Tunnel Client Settings page for the realm(s) that include the Connect Tunnel as an access agent (Realms > Access Methods > Network Tunnel Client Settings).
3. In the Windows options, select Enable post-connection scripting and then specify the location of KB4644-regfix.exe.
When users connect, the script runs automatically, without intervention, and the client will be able to auto-update correctly whenever the version number on the appliance changes.
Connect Tunnel installation
If you would prefer to distribute the client fix executable with the client setup program, you can write a batch file that deploys the Connect Tunnel client as an .exe file (ngsetup_xx>.exe), along with KB4644-regfix.exe. If you modified the ngsetup.ini file, distribute this file as well. You can also distribute it using configuration management software (with an .msi file) or as a disk image. These installation options are described in "Deploying Client Installation Packages for Connect Tunnel" in the AMC help and Installation and Administration Guide.
Tracking
BugID: 65662 (9.0.0), 65777 (8.9.0)
Related Articles
Categories