I need to connect to a Cisco VPN on Linux and at first I did this using the KDE NetworkManager plasma widget thingy. That worked fine and I'm able to connect to the VPN if I choose it from the Network Manager widget.
However, if I try using the command line things don't work (IPs and URLs have been changed to protect the innocent):
➜ ~ sudo openconnect --proxy http://proxy.mycompany.com:8080 vpn.mycompany.com:443 POST https://vpn.mycompany.com/ Attempting to connect to proxy 172.17.122.135:8080 Requesting HTTP proxy connection to vpn.mycompany.com:443 Unexpected continuation line after CONNECT response: 'Via: 1.1 SPROXY2' Unexpected continuation line after CONNECT response: 'X-WebMarshal-RequestID: 445D5E14-309A-4AA2-B7AF-07CAAD5BB21D' SSL negotiation with vpn.mycompany.com Server certificate verify failed: signer not found Certificate from VPN server "vpn.mycompany.com" failed verification. Reason: signer not found Enter 'yes' to accept, 'no' to abort; anything else to view: yes Connected to HTTPS on vpn.mycompany.com Got HTTP response: HTTP/1.0 302 Object Moved GET https://vpn.mycompany.com/ Attempting to connect to proxy 172.17.122.135:8080 Requesting HTTP proxy connection to vpn.mycompany.com:443 Unexpected continuation line after CONNECT response: 'Via: 1.1 SPROXY2' Unexpected continuation line after CONNECT response: 'X-WebMarshal-RequestID: 39FA73DC-1FDD-4C4C-A1A6-5993477DD8E3' SSL negotiation with vpn.mycompany.com Server certificate verify failed: signer not found Connected to HTTPS on vpn.mycompany.com Got HTTP response: HTTP/1.0 302 Object Moved GET https://vpn.mycompany.com/+webvpn+/index.html Requesting HTTP proxy connection to vpn.mycompany.com:443 Unexpected continuation line after CONNECT response: 'Via: 1.1 SPROXY2' Unexpected continuation line after CONNECT response: 'X-WebMarshal-RequestID: 0141A4E6-1EA7-4FAE-AFA0-E56B2BC07BD1' SSL negotiation with vpn.mycompany.com Server certificate verify failed: signer not found Connected to HTTPS on vpn.mycompany.com Please enter your username and password. GROUP: [1..VPN|2..AD]:2 Auth choice "2" not valid Failed to obtain WebVPN cookie ➜ ~ I get prompted that the certificate verification failed and then I get prompted to choose the group but then everything fails with "Auth choice "2" not valid".
I've tried different options for the openconnect command. For example -g to specify the group -u to specify the username and --no-cert-check to skip the certificate check that's failing, but nothing works.
As you can see I'm using a proxy. This may have something to do with this but I'm not sure how it is (maybe?) affecting this.
I don't get how openconnect can work via the NetworkManager KDE widget but fail on the command line. Am I missing something here?
ps axwwwor check /proc/PID entries)