Date: Thu, 17 Oct 2002 17:56:01 -0700 From: Lars Eggert <larse@ISI.EDU> To: Charles Henrich <henrich@sigbus.com> Cc: freebsd-net@freebsd.org Subject: Re: IPSEC/NAT issues Message-ID: <3DAF5C21.6000108@isi.edu> References: <20021017162243.B89519@sigbus.com> <3DAF509C.6030002@isi.edu> <20021017172905.A91625@sigbus.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Charles Henrich wrote:
> The nat daemon does not log any rejections of the packet, however in my kernel
> log, I see a
>
> Oct 17 17:23:51 dmz /kernel: Connection attempt to TCP B:3283 from C:22
Your packets don't seem to reach natd after IPsec inbound processing.
Looks like ipfw processing happens before IPsec (so natd sees the
IPsec'ed packets, but doesn't know anything about them), and gets thems
them after IPsec inbound processing. What you want is a way to do IPsec
first, and then ipfw processing, but I don't know if that can be done.
Try configuring an IPIP tunnel between B and C, and transport-mode IPsec
that. That way, your NAT packets get tunneled, and the tunneled packets
secured. On inbound, security processing comes first, then
decapsulation, then ipfw.
Lars
--
Lars Eggert <larse@isi.edu> USC Information Sciences Institute
[-- Attachment #2 --]
0 *H
010 + 0 *H
080fErtcvE.0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
000830000000Z
040827235959Z010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
*H
0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0
*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B li+@]jy.%݊
Z<D&iHΥbb090%A0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S090%A0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S1'0#0010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0 + a0 *H
1 *H
0 *H
1
021018005602Z0# *H
18Ո?жr1F0R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
1010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0
*H
?
a쭖ᳫڳ#<2-
M:\ 8嫕wl~NJ.ѥ*6Iq^ %R6HԈ_,F?"m_9#aL+
k_FR^SM .yuh!b1a!tYٽ߯C:Bh8n;*/d*ßHv9Y9JgQ4H?w5d!~/mH
jaCZ{
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3DAF5C21.6000108>
