Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 17 Oct 2002 17:56:01 -0700
From:      Lars Eggert <larse@ISI.EDU>
To:        Charles Henrich <henrich@sigbus.com>
Cc:        freebsd-net@freebsd.org
Subject:   Re: IPSEC/NAT issues
Message-ID:  <3DAF5C21.6000108@isi.edu>
References:  <20021017162243.B89519@sigbus.com> <3DAF509C.6030002@isi.edu> <20021017172905.A91625@sigbus.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Charles Henrich wrote:
> The nat daemon does not log any rejections of the packet, however in my kernel
> log, I see a 
> 
> Oct 17 17:23:51 dmz /kernel: Connection attempt to TCP B:3283 from C:22

Your packets don't seem to reach natd after IPsec inbound processing.

Looks like ipfw processing happens before IPsec (so natd sees the 
IPsec'ed packets, but doesn't know anything about them), and gets thems 
them after IPsec inbound processing. What you want is a way to do IPsec 
first, and then ipfw processing, but I don't know if that can be done.

Try configuring an IPIP tunnel between B and C, and transport-mode IPsec 
that. That way, your NAT packets get tunneled, and the tunneled packets 
secured. On inbound, security processing comes first, then 
decapsulation, then ipfw.

Lars
-- 
Lars Eggert <larse@isi.edu>           USC Information Sciences Institute

[-- Attachment #2 --]
0	*H
010	+0	*H
	080fErtcvE.0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
040827235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B	li+@]jy.%݊
Z<D&iHΥbb090%A0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0JjWV~	1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r	Hcc	U3%7N_oV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+	Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S090%A0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0JjWV~	1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r	Hcc	U3%7N_oV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+	Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S1'0#0010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0	+a0	*H
	1	*H
0	*H
	1
021018005602Z0#	*H
	18Ո?жr1F0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0
	*H
?
a쭖ᳫڳ#<2-
M:\8嫕wl~NJ.ѥ*6Iq^%R6HԈ_,F?"m_9#aL+
k_FR^SM	.yuh!b1a!tYٽ߯C:Bh8n;*/d*ßHv9Y9JgQ4H?w5d!~/mH
jaCZ{

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3DAF5C21.6000108>