{"id":2632,"date":"2020-11-20T17:29:55","date_gmt":"2020-11-21T01:29:55","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=2632"},"modified":"2020-11-21T16:42:39","modified_gmt":"2020-11-22T00:42:39","slug":"how-to-fix-ssl-negotiation-with-license-manager-server-has-failed-on-an-old-sonciwall-device","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=2632","title":{"rendered":"How to Fix &#8220;SSL Negotiation With License Manager Server Has Failed&#8221; on an Old SonicWALL Device"},"content":{"rendered":"\n<p>DESCRIPTION:<\/p>\n\n\n\n<p>Older firmware&nbsp;versions are not able to contact to the new HTTPS License&nbsp;server due to an updated certificate on our backend.<br>The new certificate is a 2048 bit certificate and uses a secure Verisign&nbsp;certificate. (new IP 204.212.170.143)<br><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808773073.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><\/p>\n\n\n\n<p>RESOLUTION:<\/p>\n\n\n\n<p><strong>Resolution A<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Upgrade at least to the latest General Release (i.e. 6.2.5.3, 6.2.7.1, 5.9.1.7)<\/li><\/ul>\n\n\n\n<p><strong>Resolution B (workaround) in the case you prefer not upgrading the firmware:<\/strong><\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/images\/content_caution.gif\" alt=\"\">&nbsp;<strong>CAUTION:<\/strong>&nbsp;This workaround may not work. The firmware upgrade is&nbsp;<strong>always<\/strong>&nbsp;the suggested solution to this issue as there might be certificate or TLS incompatibilities with old firmware versions.<\/p>\n\n\n\n<p>Step 1: Create a DNS entry on your internal DNS server to resolve to the OLD&nbsp;License manager IP 204.212.170.35<br><br>Screenshot below shows an example server 192.168.168.101 (DNS Server) which has an entry for licensemanager.sonicwall.com<br>It resolves to the old IP 204.212.170.35 (old SonicWall Licenseserver which accepts&nbsp;old root certificates from old firmware versions)<br><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808474986.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><br>Step 2: Put the internal DNS as the first choice in the firewall&nbsp;<strong>Network | DNS | Settings<\/strong>&nbsp;.&nbsp;<br>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Let&#8217;s say the internal DNS server is 192.168.168.101, then put 192.168.168.101 in the first field (first choice)<br><br>Step 3: Import the certificate from the https:\/\/204.212.170.35 webpage.&nbsp;<br>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;You can use, for example, Firefox to download the certificate. If this&nbsp;does not work, you can also carry out&nbsp;the following steps to import the&nbsp;certificate.<\/p>\n\n\n\n<p>1. Navigate to the&nbsp;<strong>System | Certificates<\/strong>&nbsp;page.&nbsp;<br>2. Under Additional CA Certificates, import the SonicWall Firewall DPI-SSL root certificate.&nbsp;<\/p>\n\n\n\n<p>TIP: The certificate can be obtained by copy-pasting the following PEM encoded text into a text editor and saving it as SonicWallFirewallDPI-SSL.pem (with .pem extension).&nbsp;<\/p>\n\n\n\n<p><br><br>&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;&nbsp;<br>MIIC6zCCAlSgAwIBAgIJAMCocw7Ocp2\/MA0GCSqGSIb3DQEBBQUAMFgxCzAJBgNV&nbsp;<br>BAYTAlVTMQswCQYDVQQIEwJDQTEXMBUGA1UEChMOU29uaWNXQUxMIEluYy4xIzAh&nbsp;<br>BgNVBAMTGlNvbmljV0FMTCBGaXJld2FsbCBEUEktU1NMMB4XDTA5MDMwOTIxMzky&nbsp;<br>MFoXDTI5MDMwNDIxMzkyMFowWDELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRcw&nbsp;<br>FQYDVQQKEw5Tb25pY1dBTEwgSW5jLjEjMCEGA1UEAxMaU29uaWNXQUxMIEZpcmV3&nbsp;<br>YWxsIERQSS1TU0wwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM9Sr0ViM9Uf&nbsp;<br>QDPE1110vQpZkbBMJdUWTGcomx8lk\/8je38O+GjrS1zEbww7JJ9GEM8PYnPxN9pA&nbsp;<br>mChtSNy5bviQdNqXfAMhSxRHICg4lFcsa95bzoRm1UzD09jXqsJQO8BR6bmLE+XZ&nbsp;<br>YnA\/QF+W7ain589WkCS3ER9gptwuw683AgMBAAGjgbwwgbkwHQYDVR0OBBYEFFdA&nbsp;<br>z3naeZEhRpUg4MfD2Dg93nmoMIGJBgNVHSMEgYEwf4AUV0DPedp5kSFGlSDgx8PY&nbsp;<br>OD3eeaihXKRaMFgxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTEXMBUGA1UEChMO&nbsp;<br>U29uaWNXQUxMIEluYy4xIzAhBgNVBAMTGlNvbmljV0FMTCBGaXJld2FsbCBEUEkt&nbsp;<br>U1NMggkAwKhzDs5ynb8wDAYDVR0TBAUwAwEB\/zANBgkqhkiG9w0BAQUFAAOBgQCm&nbsp;<br>kgRiH8A1r6in0u3iAqFBuiNDdkqefVOZAULEplx00\/kETR5m3IOurG+pKln4SmNp&nbsp;<br>lZgxA6\/ldr+wPgXQD72mbXUHDLIaSernjMhNC1MxhVGiXTGLyYL2ULv52mk8EIzY&nbsp;<br>Qxk7DWfLJqCuUyZ59+spkQu40uTZX14Dc\/uM142bJg==&nbsp;<br>&#8212;&#8211;END CERTIFICATE&#8212;&#8211;&nbsp;<\/p>\n\n\n\n<p>OR&nbsp;<\/p>\n\n\n\n<p>the certificate can be exported by accessing Https:\/\/204.212.170.35 from any Internet browser, here is an example on exporting the SonicWall Firewall DPI-SSL certificate using the latest FireFox browser.<\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808328165.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><br><br><strong>How to Test:<\/strong><\/p>\n\n\n\n<p>1) First test is to check if the SonicWall resolves to the old licensemanager ip.<br>Go to&nbsp;<strong>System | Diagnostic<\/strong>&nbsp;and then check if the name licensemanager.sonicwall.com resolves&nbsp;to 204.212.170.143,&nbsp;and check if the first (the internal DNS) is being used.<br><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808895721.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><br>2) Then go to&nbsp;<strong>System | Certificate<\/strong>&nbsp;and check if you see the new imported certificate<br><img decoding=\"async\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808956401.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><br>3a) Go the&nbsp;<strong>System | Registration<\/strong>&nbsp;and click on&nbsp;<strong>Registration<\/strong>. If you are redirected to a Login Page then the workaround works<br>&nbsp;&nbsp; &nbsp;Login with your mysonicwall.com credentials with your Username and Password<br>&nbsp;&nbsp; &nbsp;(the same Password which you use for your mysonicwall.com account)<\/p>\n\n\n\n<p>or&#8230;<br><br>3b) You can also go to&nbsp;<strong>System | Licenses | License renew<\/strong>&nbsp;(below the Synchronize&nbsp;button). If you click on this link, then it redirects you as well to the mySonicWall account . You should see here a Login Page as well<br><img fetchpriority=\"high\" decoding=\"async\" width=\"612\" height=\"480\" src=\"https:\/\/sonicwall.rightanswers.com\/portal\/app\/portlets\/results\/onsitehypermedia\/090170808607611.png?linkToken=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE2Mzc0NTM1NzEsImlhdCI6MTYwNTkxNzU3MX0.Opv40RfPeZ6JA8X7tB9xFIwxs6ywQLJO17OPDggfeO0\" alt=\"Image\"><\/p>\n\n\n\n<p>REF: https:\/\/www.sonicwall.com\/support\/knowledge-base\/error-message-ssl-negotiation-with-license-manager-server-has-failed\/170505570663153\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DESCRIPTION: Older firmware&nbsp;versions are not able to contact to the new HTTPS License&nbsp;server due to an updated certificate on our backend.The new certificate is a 2048 bit certificate and uses a secure Verisign&nbsp;certificate. (new IP 204.212.170.143) RESOLUTION: Resolution A Upgrade at least to the latest General Release (i.e. 6.2.5.3, 6.2.7.1, 5.9.1.7) Resolution B (workaround) in <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=2632\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[13,52,9],"tags":[435,437],"class_list":["post-2632","post","type-post","status-publish","format-standard","hentry","category-firewalls","category-hardware","category-networks","tag-register-a-old-sonicwall","tag-ssl-negotiation-with-license-manager-server-has-failed"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/2632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2632"}],"version-history":[{"count":3,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/2632\/revisions"}],"predecessor-version":[{"id":2635,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/2632\/revisions\/2635"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2632"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2632"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}