Netscreen VPN NAT

This is a discussion on Netscreen VPN NAT within the IPFilter forums, part of the System Security and Security Related category; Solaris 10 Ipfilter 4.1.5 (plus patches making it 4.1.6ish). No ipf.conf rules, standard NAT only ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-26-2006
Jorgen Lundman
 
Posts: n/a
Default Netscreen VPN NAT


Solaris 10
Ipfilter 4.1.5 (plus patches making it 4.1.6ish).

No ipf.conf rules, standard NAT only rules:


map e1000g0 192.168.0.0/16 -> extint/32 proxy port ftp ftp/tcp
map e1000g0 192.168.0.0/16 -> extint/32 portmap tcp/udp auto
map e1000g0 192.168.0.0/16 -> extint/32



For some reason the "network team" decided that they want to VPN from 192.168/16
to a Netscreen in the other datacenter.

They find that the first session works well, but not the second etc. My initial
guess is that the first session gets port 500, and the following do not.

Checking the FAQ, and this list, it would appear I should add:

#map extint from rfc1918/24 port=500 to vpnip/32 -> publicip/32
#map extint rfc1918/24 -> publicip/32 proxy port 500 ipsec/udp

At the top of ipnat.conf, in that other.

However, when I add these two lines, the other (non-VPN) NAT'ing grinds to a
halt. Sort of works, but like surfing through molasses.

Has there been any bug fixes with the VPN proxy code recently that could account
for the NAT'ing being affected by just adding these rules? We haven't actually
got to trying if the VPN's will work, since it creates havoc whenever I add the
rules.

(Removing rules, and ipnat -CF get it back again).

The Changelog on the ipfilter webpage only talks about v3 series.

Lund

--
Jorgen Lundman | <lundman@lundman.net>
Unix Administrator | +81 (0)3 -5456-2687 ext 1017 (work)
Shibuya-ku, Tokyo | +81 (0)90-5578-8500 (cell)
Japan | +81 (0)3 -3375-1767 (home)
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:07 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0