Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 06 Mar 2001 17:19:59 -0800
From:      Lars Eggert <larse@ISI.EDU>
To:        Stephen Cimarelli <stephen@clari.net.au>
Cc:        freebsd-net@freebsd.org
Subject:   Re: IPSEC + natd + IPFW
Message-ID:  <3AA58CBF.819707E6@isi.edu>
References:  <XFMail.010307120903.stephen@clari.net.au>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Stephen Cimarelli wrote:
> I have managed to get IPsec+gif tunelling to work but am having trouble setting
> up firewal rules, it seem that recieved ESP packets pass through the firewall
> rule set  twice and  hit my natd divert rules.

Do you use IPsec tunnel mode, or IPsec transport mode + gif tunnels to do
the tunneling? Also, in the ipfw rules below, your "via" clauses reference
tun0, which is neither gif nor IPsec tunneling.

> Toget around this I had to add a rule like 00110 and 00115
> 
> 00001   150   20400 count esp from any to any
> 00010   150   20400 allow esp from any to any in recv tun0
> 00011     0       0 allow esp from any to any out xmit tun0
> 00110  1560  231661 allow ip from 192.168.0.0/16 to 192.168.0.0/16
> 00115     9     756 allow ip from 10.10.0.0/16 to 192.168.0.0/16 via tun0
> 00120  6193 2543953 divert 8668 tcp from any to any out xmit tun0
> 00120    15    1233 divert 8668 udp from any to any out xmit tun0
> 00120     0       0 divert 8668 icmp from any to any out xmit tun0
> 00121  6132 6364485 divert 8668 tcp from any to any in recv tun0
> 00121    16    3516 divert 8668 udp from any to any in recv tun0
> 00121    21    1764 divert 8668 icmp from any to any in recv tun0
-- 
Lars Eggert <larse@isi.edu>                 Information Sciences Institute
http://www.isi.edu/larse/                University of Southern California
[-- Attachment #2 --]
0#	*H
010	+0	*H
00A#0
	*H
010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160
000824203008Z
010824203008Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0\p9޻ H;v֐r∩6"C?mxfJf7I[3CF́L	I
-zHRVA怤2]0-bL)%X>nӅw0u0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00U#0`fUXFa#Ì0
	*H
_3	F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
990916140140Z
010915140140Z010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600
	*H
0iZz]!#rLK~r$BRW{azr98e^eyvL>hput,O	1ArƦ]D.Mօ>lx~@эWs0FO7050U00U#0rIs4Uvr~wƲ0
	*H
kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6-	-mƃRt\~
orzg,ksnΝc)	~U100010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0	+0	*H
	1	*H
0	*H
	1
010307011959Z0#	*H
	1l6K#;ah0R	*H
	1E0C0
*H
0*H
0+0
*H
@0
*H
(0
	*H
FB'a2⯟b	@Yy,Ֆ<@rT23MXԴ*Rٽ(	QZW;)3UVj>#eU׮'9?i`W^Єu]<

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AA58CBF.819707E6>