HandiTax Lodgement: VPN Timed Out Waiting For Client Response Timed Out Waiting For VPN Client Response CISCO VPN CISCO VPN is the program that the ATO use to allow lodgements to be made via their ELS system. Should you encounter an issue that relates to the CISCO VPN program, HandiSoft is limited in the extent that we can offer assistance, therefore the following article should be used as a guide only and if your issue is not resolved it would be best to contact the ATO on 137286 Fast Key Code 31 ELS: VPN error "Timed out waiting for VPN client response" If you encounter a "Timed out waiting for VPN client response" error message when trying to lodge using the CISCO VPN client through the ATO's Electronic Lodgement System, the following article sets out a few options to try and resolve the issue. To troubleshoot the issue it is best to try and establish a Manual VPN Connection to see if there is an underlying reason that may be causing the issue. There are a number of items that can be checked first: 1) Antivirus / Firewall programs Add the CISCO VPN Client to your exception list. 2) VPN Missing Host numbers Starting the VPN Client program the following window should appear. Page 1 of 9
It is important that there are the same four Connection Entries as pictured above and each have the same corresponding Host numbers. The HandiSoft Software CD can be used to add any missing Host numbers. The *.pcf files can be found on the CD Drive:\AutoPlay\ciscoVPN\PCF directory. Unzip and decompress the files to your VPN Client directory. (C:\Program Files\Cisco Systems\VPN Client\Profiles or C:\Program Files (x86)\cisco Systems\VPN Client\Profiles) This will then ensure that the correct Server Host IPs are filled in for the Connection Entries. Continue with the VPN Manual Connection. 3) VPN Connection Entry to use To check the VPN Connection Entry, in HandiTax from the Options menu, click ELS Communications and check the Profile for the ELS Approval Number. Page 2 of 9
The first digit in the ELS approval number will help determine which Primary CEG needs to chosen. The Primary CEG determines which connection profile is used in the VPN Client. 1 or 2: ADE: MelAde or imelade 3 or 4: BR: SydBri or isydbri 5 or 6: ME: MelAde or imelade 7 or 8:SYD:SydBri or isydbri Depending on the settings and configuration, use the applicable one for the VPN Manual Connection. The difference in the connection entries between something like MelAde and imelade is which connection method you use. If you use broadband internet (LAN, DSL or cable, this includes wireless broadband or WIFI connections) then you would be interested in the connection entry with the leading "i" in front. The connection entry without the "i" are for "Dial IP" (analogue modem) connections. Note: ATO Access Codes for VPN Code 1 and Code 2 are your user authentication details for the Cisco VPN Client. Code 1 = username. Code 2 = password. If any of these details are missing, please consult the original letter received from the ATO when ELS was originally applied for. These details never change for the lifetime of the Tax Agent Number. You may need to contact the ATO to obtain these details if necessary. 4) Creating a manual VPN connection to troubleshoot the "Timed out waiting for VPN client response" error message Start the CISCO VPN Program from the Windows Start Menu or by navigating to the vpngui.exe file through My Computer. Page 3 of 9
If the VPN Client starts normally and valid host numbers are visible for each connection entry, the matter may have to be referred to the ATO. However, listed below are some steps you can try to discover the underlying reason to the timeout. 5) VPN Manual Connection First you need to establish a manual connection. Right-click the Connection Entry normally used and choose Connect. If prompted for the Authentication details, complete them accordingly. If the VPN Client connects successfully, the VPN Client will minimise to the system tray. If it fails,the following error messages may appear: Page 4 of 9
Reason 412: Remote peer is no longer responding Reason 413: User authentication failed Reason 442: Unable to enable virtual adapter Potential error messages if the connection fails: Reason 412: Remote peer is no longer responding Although the message appears that the error may be coming from the ATO end (remote peer) the problem is more likely on the local end. Something on the local machine/network is stopping the communication to the VPN hosts. In this case, there are a number of things you can try: 1. Disable all firewall hardware/software implementations. 2. Disable all antivirus programs. 3. Change the VPN Transport Protocol Reason 413: User authentication failed This is usually due one of the following reasons: 1. For the particular username entered, the password is incorrect, or 2. For the particular username entered, the account has been locked. Note: If this account is locked, it is only limited to this particular Host Server (Connection Entry) for the next 24 hours. Any new attempts to log in to this Host for that username will renew the 24 hour lockout period. If this happens then try the "other" connection entry to see if it is successful. Ie. If you tried connecting to imelade and you get this Reason 413, then try a manual connection to isydbri. Only try this once! If the other host (Connection Entry) accepts your authentication details, then that would confirm reason 2 as above. In this case, you will want to stay on this other host until the 24 hour lockout period expires, then you can safely switch back. remember, from the information in Which Connection Entry do I use? You can set HandiTax to use a particular host (Connection Entry). I.e. Choose the appropriate Primary CEG that will result in the desired host to be logging in through. If the other host (Connection Entry) rejects your authentication details, then more than likely your password (code 2) is incorrect. Please double check your ATO Access Page 5 of 9
Codes for VPN password. It should be 10 characters long. No capital letters. No number 1 or number 0. Reason 442: Unable to enable virtual adapter If you get this error message - the computer is having a problem loading certain modules to be able to establish the VPN Connection. This can occur because Internet Connection Sharing (ICS) is enabled: 1. Right-click on Local Area Connection in the status bar and select Status and then Properties. 2. Click the Sharing tab. 3. Un-select Allow other network users to connect through to this computer's internet connection. 4. Click Ok. Windows 8 and Reason 442 If you are using Windows 8 and receive Reason 442, please complete the steps below: Note: Before you make changes to a registry key or subkey, we recommend that you backup the registry or export, or make a backup copy of, the key or subkey. You can save the backup copy to a location you specify, such as a folder on your hard disk or a removable storage device. If you make changes that you want to undo, you can import the backup copy. 1. Enter the Registry Editor, by holding down the Windows Key + R 2. Type in regedit and click OK to execute. Page 6 of 9
3. Amend the applicable registry entry by navigating to the registry hive locate HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CVirtA 4. Edit the DisplayName the current incorrect key may show something like @oem4.inf,%cvirta_desc%;cisco Systems VPN Adapter for 64-bit Windows. 5. Delete all the leading characters only before the word Cisco in the key so that it reads: Cisco Systems VPN Adapter for 64-bit Windows or Cisco Systems VPN Adapter depending on whether it is 64-bit or 32-bit Windows. If this does not solve your issue you then try uninstalling and reinstalling the VPN Client, and if this does not resolve the issue, it will need to referred to the ATO. Modifying VPN Transport Protocol You can change the method by which the communication travels to the VPN Host. By default it is IPSec/UDP. You can try IPSec/TCP to see if there are any improvements. Right-click on the Connection Entry concerned and choose Modify. Click on the Transport tab and change to IPSec over TCP using Port 10000. Or IPSec over UDP (NAT/PAT) if already on TCP. Page 7 of 9
Try the VPN Manual Connection again. If you continue to get Error 412 you may need to escalate to your own IT department to assist with the networking side of things. Your alternative would be to try another computer within your network. Warning 203: You do not have write privileges for this connection entry When trying to modify your VPN connection entry, you may the error message below. As you can see, it will be opened as read-only so there is no point making any changes. You will need to logout and re-login as Administrator and try again. Error 56: VPN Service not started You may get this message when VPN Client is trying to load Page 8 of 9
The VPN Client does not appear to have started when the PC booted up. To manually start it from the Control Panel go to Administrative Tools and Services, find CISCO Systems in the list. Right click and choose Start. Once the service is started, you should be able to start the VPN Client and continue with the VPN Manual Connection. Error 51: Unable to communicate with the VPN Subsystem The message states "Unable to communicate with the VPN Subsystem. Please make sure you have at least one network interface that is currently active and has an IP address and start this application again." Please ensure you have an active working internet connection then restart your VPN Service. Similar to the steps above in "Error 56", open Control Panel and go to Administrative Tools then Services, find CISCO Systems in the list. Right-click and choose Stop. Then right-click and choose Start. Once the service has been restarted, you should be able to start the VPN Client and continue with the VPN Manual Connection. Page 9 of 9