After setting up the hub tunnel and certificate we cannot get the tunnel to connect.
The client side hub logs show the following errors:
May 9 15:23:33:849 [2832] hub: SSL handshake start from ##.##.##.##/48003: before/connect initialization
May 9 15:23:33:849 [2832] hub: SSL state (connect): before/connect initialization
May 9 15:23:33:849 [2832] hub: SSL state (connect): SSLv3 write client hello A
May 9 15:23:33:880 [2832] hub: ssl_connect - SSL_connect error (5) on new SSL connection
May 9 15:23:33:880 [2832] hub: SSL_connect error occured
May 9 15:23:33:880 [2832] hub: TSESS could not connect to tunnel ##.##.##.##:48003 (0)
May 9 15:23:33:880 [2832] hub: CTRL could not connect to server ##.##.##.##/48003
The server side Hub logs show:
May 9 15:09:38:129 [140089799726848] hub: TSESS-A-47-124 session looping (60) wait_time is now: 605
May 9 15:09:38:199 [140090869274368] hub: SSL handshake start from ##.##.##.##/63959: before/accept initialization
May 9 15:09:38:199 [140090869274368] hub: SSL state (accept): before/accept initialization
May 9 15:09:38:205 [140090051352320] hub: Sent heartbeat on queue route 'Audit_to_On-Prem'
May 9 15:09:38:211 [140090869274368] hub: SSL alert (write): fatal: handshake failure
May 9 15:09:38:211 [140090869274368] hub: ssl_server_wait - SSL_accept error (1) on new SSL connection: ##.##.##.##
May 9 15:09:38:211 [140090869274368] hub: [1] error:0x1408A0C1:SSL routine:SSL3_GET_CLIENT_HELLO:no shared cipher
You are able to telnet to the proper IP address and port, a wire-shark trace route looks normal.
DX UIM 20.4.* / 23.4.*
There may be other causes.
Note: This issue is not hub or UIM specific. The problem is external to Nimsoft/UIM and can be seen on any hub version running a tunnel.
Removing the "SSL Decryption" setting or adding an exception for your servers should help establish a tunnel connection.