Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 03 Feb 2009 14:29:22 +0100
From:      Sebastiaan van Erk <sebster@sebster.com>
To:        freebsd-pf@FreeBSD.org
Subject:   Re: GRE not natted on FreeBSD 7.1-p2
Message-ID:  <498846B2.1080306@sebster.com>
In-Reply-To: <49882A91.3050307@sebster.com>
References:  <49882A91.3050307@sebster.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hi,

I changed the GRE rule to:

pass out quick proto gre

and it was still giving me the same errors after flushing the firewall:

pfctl -f /etc/pf.conf

Log:

3. 003875 rule 6/0(match): block out on vr0: 10.1.0.6 > 193.46.80.81: 
GREv1, call 55191, seq 7, proto PPP (0x880b), length 36: [|ppp]

But a few minutes later I started up the VPN (without having changed 
anything in the firewall), and now it suddenly did work.

I don't know where the delay comes from, I've never seen that before...

Regards,
Sebastiaan

Sebastiaan van Erk wrote:
> Hi,
> 
> I've just upgraded my old old old FreeBSD 6.3 firewall box to FreeBSD 
> 7.1-p2.
> 
> However, now my firewall will suddenly no longer NAT GRE, so none of 
> client connections to remote (PPTP) VPNs are working.
> 
> When trying to connect from the client (10.1.0.6) to internet, 
> everything works fine (tcp/udp are natted), but when trying to set up a 
> VPN my firewall log says:
> 
> 3. 004630 rule 6/0(match): block out on vr0: 10.1.0.6 > 193.46.80.81: 
> GREv1, call 55191, seq 10, proto PPP (0x880b), length 36: [|ppp]
> 
> (vr0 is my external interface, which is connected to the ADSL modem)
> 
> The rule that is blocking is:
> @6 block drop out log quick on vr0 inet from ! 192.168.1.2 to any
> 
> (192.168.1.2 is my "external" address). This rule is supposed to block 
> any internal stuff going out that is not NATted properly. It is correct 
> to block my client (10.1.0.6), since it should have had its address 
> translated.
> 
> My nat rule is simple (and DOES NAT tcp/udp):
> 
> nat on $ext_if from { $int_net, $wifi_net } to any -> $ext_if
> 
> The entire config is attached. Am I doing something stupid? Does anybody 
> know what I'm doing wrong?
> 
> Thanks in advance,
> Sebastiaan
> 
> 
> 

[-- Attachment #2 --]
0	*H
010	+0	*H
	Q00lS|
6$1-~j0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 	*H
	sebster@sebster.com0"0
	*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I	x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/00.0U0sebster@sebster.com0U00
	*H
KT4W6ӽq]
tS` %f1G:HbzJj$EjE'JV~-VbVnJZE/`@@04!+T:c	پf`$Z=1#|oG[OBRG00lS|
6$1-~j0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 	*H
	sebster@sebster.com0"0
	*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I	x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/00.0U0sebster@sebster.com0U00
	*H
KT4W6ӽq]
tS` %f1G:HbzJj$EjE'JV~-VbVnJZE/`@@04!+T:c	پf`$Z=1#|oG[OBRG0?0
0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
030717000000Z
130716235959Z0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00
	*H
0Ħ<UsUNʙZhup[v:aQP
0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr`00U00CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380
	*H
HP.
fgCL!6-6/P p<ab:~t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1q0m0v0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0	+0	*H
	1	*H
0	*H
	1
090203132922Z0#	*H
	1uB%FN%<0_	*H
	1R0P0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+71x0v0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0*H
	1xv0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0
	*H
7w%ˆD=z2ۧF=kt$nῠVxbbq+?SuBDF#ǹTHlSHAu\w
/*=]\!xQ-cTz{dq׶MRC*џ2۶C'`{VQtlXͯX.~(8ѮoFFq#EtQ*-HH)A~$J/:

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?498846B2.1080306>