Date: Tue, 06 Mar 2001 17:19:59 -0800 From: Lars Eggert <larse@ISI.EDU> To: Stephen Cimarelli <stephen@clari.net.au> Cc: freebsd-net@freebsd.org Subject: Re: IPSEC + natd + IPFW Message-ID: <3AA58CBF.819707E6@isi.edu> References: <XFMail.010307120903.stephen@clari.net.au>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Stephen Cimarelli wrote: > I have managed to get IPsec+gif tunelling to work but am having trouble setting > up firewal rules, it seem that recieved ESP packets pass through the firewall > rule set twice and hit my natd divert rules. Do you use IPsec tunnel mode, or IPsec transport mode + gif tunnels to do the tunneling? Also, in the ipfw rules below, your "via" clauses reference tun0, which is neither gif nor IPsec tunneling. > Toget around this I had to add a rule like 00110 and 00115 > > 00001 150 20400 count esp from any to any > 00010 150 20400 allow esp from any to any in recv tun0 > 00011 0 0 allow esp from any to any out xmit tun0 > 00110 1560 231661 allow ip from 192.168.0.0/16 to 192.168.0.0/16 > 00115 9 756 allow ip from 10.10.0.0/16 to 192.168.0.0/16 via tun0 > 00120 6193 2543953 divert 8668 tcp from any to any out xmit tun0 > 00120 15 1233 divert 8668 udp from any to any out xmit tun0 > 00120 0 0 divert 8668 icmp from any to any out xmit tun0 > 00121 6132 6364485 divert 8668 tcp from any to any in recv tun0 > 00121 16 3516 divert 8668 udp from any to any in recv tun0 > 00121 21 1764 divert 8668 icmp from any to any in recv tun0 -- Lars Eggert <larse@isi.edu> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California [-- Attachment #2 --] 0# *H 010 + 0 *H 00A#0 *H 010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160 000824203008Z 010824203008Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu00 *H 0 \p9 H;vr∩6"C?mxfJf7I[3CF́L I - zHRVA怤2]0-bL)%X>nӅ w0u0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0U#0`fUXFa#Ì0 *H _3 F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 990916140140Z 010915140140Z010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600 *H 0 iZz]!#rLK~r$BRW{azr98e^eyvL>hput ,O 1ArƦ]D.Mօ>lx~@эWs0FO 7050U0 0U#0rIs4Uvr~wƲ0 *H kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6- -mƃRt\~ orzg,ks nΝc) ~U100010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0 + 0 *H 1 *H 0 *H 1 010307011959Z0# *H 1l6K#;ah0R *H 1E0C0 *H 0*H 0+0 *H @0 *H (0 *H FB'a2⯟b @Yy,Ֆ<@rT 23MXԴ*Rٽ( QZW;)3UVj>#eU'9?i`W^Єu]<
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AA58CBF.819707E6>
