Date: Tue, 03 Feb 2009 14:29:22 +0100 From: Sebastiaan van Erk <sebster@sebster.com> To: freebsd-pf@FreeBSD.org Subject: Re: GRE not natted on FreeBSD 7.1-p2 Message-ID: <498846B2.1080306@sebster.com> In-Reply-To: <49882A91.3050307@sebster.com> References: <49882A91.3050307@sebster.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Hi,
I changed the GRE rule to:
pass out quick proto gre
and it was still giving me the same errors after flushing the firewall:
pfctl -f /etc/pf.conf
Log:
3. 003875 rule 6/0(match): block out on vr0: 10.1.0.6 > 193.46.80.81:
GREv1, call 55191, seq 7, proto PPP (0x880b), length 36: [|ppp]
But a few minutes later I started up the VPN (without having changed
anything in the firewall), and now it suddenly did work.
I don't know where the delay comes from, I've never seen that before...
Regards,
Sebastiaan
Sebastiaan van Erk wrote:
> Hi,
>
> I've just upgraded my old old old FreeBSD 6.3 firewall box to FreeBSD
> 7.1-p2.
>
> However, now my firewall will suddenly no longer NAT GRE, so none of
> client connections to remote (PPTP) VPNs are working.
>
> When trying to connect from the client (10.1.0.6) to internet,
> everything works fine (tcp/udp are natted), but when trying to set up a
> VPN my firewall log says:
>
> 3. 004630 rule 6/0(match): block out on vr0: 10.1.0.6 > 193.46.80.81:
> GREv1, call 55191, seq 10, proto PPP (0x880b), length 36: [|ppp]
>
> (vr0 is my external interface, which is connected to the ADSL modem)
>
> The rule that is blocking is:
> @6 block drop out log quick on vr0 inet from ! 192.168.1.2 to any
>
> (192.168.1.2 is my "external" address). This rule is supposed to block
> any internal stuff going out that is not NATted properly. It is correct
> to block my client (10.1.0.6), since it should have had its address
> translated.
>
> My nat rule is simple (and DOES NAT tcp/udp):
>
> nat on $ext_if from { $int_net, $wifi_net } to any -> $ext_if
>
> The entire config is attached. Am I doing something stupid? Does anybody
> know what I'm doing wrong?
>
> Thanks in advance,
> Sebastiaan
>
>
>
[-- Attachment #2 --]
0 *H
010 + 0 *H
Q00lS|
6$1-~j0
*H
0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 *H
sebster@sebster.com0"0
*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/ 00.0U0sebster@sebster.com0U0 0
*H
KT4W6ӽq]
tS` %f1G:H b zJj$EjE'JV~-VbVnJZE/`@@04!+T:c پf`$Z=1#|oG[OBRG00lS|
6$1-~j0
*H
0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 *H
sebster@sebster.com0"0
*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/ 00.0U0sebster@sebster.com0U0 0
*H
KT4W6ӽq]
tS` %f1G:H b zJj$EjE'JV~-VbVnJZE/`@@04!+T:c پf`$Z=1#|oG[OBRG0?0
0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
030717000000Z
130716235959Z0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00
*H
0 Ħ<UsUNʙZhup[v:aQP
0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr` 00U0 0CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380
*H
HP.
fgCL!6-6/P p<ab:~ t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1q0m0v0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0 + 0 *H
1 *H
0 *H
1
090203132922Z0# *H
1uB%FN%<0_ *H
1R0P0 `He0
*H
0*H
0
*H
@0+0
*H
(0 +71x0v0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0*H
1xv0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0
*H
7w%ˆD=z2ۧF=kt$nῠVxbbq+?SuBDF#ǹTHlSHAu\w
/*=]\!xQ-cTz{dqMRC*џ2۶C'`{VQtlXͯX.~(8ѮoFFq#EtQ*-HH)A~$J/:
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?498846B2.1080306>
