VPNC and ipfilter

This is a discussion on VPNC and ipfilter within the IPFilter forums, part of the System Security and Security Related category; Hi all, I am using VPNC on my freebsd 6.1 I have no problem to start the vpnc and ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-11-2006
Jan Rockstedt
 
Posts: n/a
Default VPNC and ipfilter

Hi all,

I am using VPNC on my freebsd 6.1
I have no problem to start the vpnc and my routing is working ok.
Interface tun0 is ok.

I have test this:
-----------
# ipnat.rules:

map xl0 192.168.1.0/24 -> 0.0.0.0/32 proxy port 500 ipsec/udp
-----------
# ipf.rules:

pass out quick on tun0 proto tcp from any to any keep state
pass out quick on tun0 proto udp from any to any keep state
pass out quick on tun0 proto icmp from any to any keep state

pass in quick on tun0 proto tcp from any to any keep state
pass in quick on tun0 proto udp from any to any keep state
pass in quick on tun0 proto icmp from any to any keep state
----------
#ipf -V
ipf: IP Filter: v4.1.8 (416)
Kernel: IP Filter: v4.1.8
Running: yes
Log Flags: 0 = none set
Default: block all, Logging: available
Active list: 0
Feature mask: 0x10a


But still i can't connect to any host behind the vpn servern.
Any sugestion why?

Regards Jan

Reply With Quote
  #2 (permalink)  
Old 05-11-2006
aka Floyd
 
Posts: n/a
Default Re: VPNC and ipfilter

Jan Rockstedt wrote:
> Hi all,
>
> I am using VPNC on my freebsd 6.1
> I have no problem to start the vpnc and my routing is working ok.
> Interface tun0 is ok.
>
> I have test this:
> -----------
> # ipnat.rules:
>
> map xl0 192.168.1.0/24 -> 0.0.0.0/32 proxy port 500 ipsec/udp
> -----------
> # ipf.rules:
>
> pass out quick on tun0 proto tcp from any to any keep state
> pass out quick on tun0 proto udp from any to any keep state
> pass out quick on tun0 proto icmp from any to any keep state
>
> pass in quick on tun0 proto tcp from any to any keep state
> pass in quick on tun0 proto udp from any to any keep state
> pass in quick on tun0 proto icmp from any to any keep state
> ----------
> #ipf -V
> ipf: IP Filter: v4.1.8 (416)
> Kernel: IP Filter: v4.1.8
> Running: yes
> Log Flags: 0 = none set
> Default: block all, Logging: available
> Active list: 0
> Feature mask: 0x10a
>
>
> But still i can't connect to any host behind the vpn servern.
> Any sugestion why?
>
> Regards Jan
>


Hi,

do your clients have a route back to the vpnc?
What does tcpdump give you?

HTH

Goetz
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:56 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0