LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-23-2009, 12:15 PM   #1
khalo
LQ Newbie
 
Registered: Sep 2009
Posts: 1

Rep: Reputation: 0
VPN thorugh iptables firewall


Hi everybody, thanks a lot for reading this. Recently my company started using a VPN hardware based solution provided by a third company the ISP. The VPN is implemented using Cisco Routers 857. My company has a remote office, so the VPN communicates our main office with the remote office (2 Cisco 857, one for each office).
At the main office we have a Linux (Fedora Core 8) Host working as e-mail server (imap/pop3), proxy server (squid) and firewall (iptables), it´s also the only host connected directly to the router (Cisco 857), all the hosts in the main Office LAN are connected to this Linux Host. At the remote office all the hosts are conected directly to the router ((Cisco 857)).
The ISP made all the configuration, but the result it´s not what i was waiting: the remote office can't access the main office´s LAN, but can only access the Linux Host. The main office can access the remote office´s LAN properly.
I asked the ISP about this issue and they said there is a wrong/missing configuration in my Linux Host, they said i should brige the interfaces. After doing this i tried accessing my main office´s LAN from a remote office host but still not working, i also tried the tracert command (under Windows XP) in the same machine, but the result didn´t seem correct to me.
I´m attaching an image showing my topology, the tracert output and the iptables rule i used.

Topology:
http://img260.imageshack.us/img260/3564/vpnac.jpg

Tracert output command:

(at a remote office Winwdows host)\tracert 192.168.1.2

Tracing route to 192.168.1.2 over a maximum of 30 hops

1 79 ms <1 ms <1 ms 10.10.20.10
2 126 ms 126 ms 134 ms 172.17.137.1
3 63 ms 141 ms 140 ms 192.168.1.2

(at a remote office Winwdows host)\tracert 10.10.10.10

Tracing route to 10.10.10.10 over a maximum of 30 hops

1 79 ms 79 ms 79 ms 10.10.20.10
2 * * * Request timed out.
3 * * * Request timed out.
4 119 ms 120 ms 123 ms 10.111.0.93
5 40 ms 120 ms 119 ms 10.7.1.22
6 * * * Request timed out.
7 * * * Request timed out.
8 * * * Request timed out.
... (same message from line 9 to 28)
29 * * * Request timed out.
30 * * * Request timed out.

Trace complete.

Rule used:
iptables -A FORWARD -s 10.10.20.0/24 -d 10.10.10.0/24 -j ACCEPT

How can i solve this issue?, does it depend on me or the ISP?. Thanks in advance.
 
Old 10-25-2009, 03:07 AM   #2
janoszen
Member
 
Registered: Oct 2009
Location: Budapest
Distribution: Mostly Gentoo, sometimes Debian/(K)Ubuntu
Posts: 143

Rep: Reputation: 22
Route?

You do have your routes configured on the firewall AND your Cisco, right? Do a tcpdump on the firewall to see, if packets are getting through and paste a dump of your routing tables on the Cisco and the firewall please.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN Firewall Solution Rycharde Linux - Security 1 03-24-2008 12:47 AM
Iptables with iptables-firewall.conf arno's matt3333 Slackware 16 06-28-2007 07:20 AM
How to access VPN + LAN in iptables Firewall pradeepjagtap Linux - Security 4 10-24-2006 12:08 AM
Redhat Firewall VPN dwpondscum Red Hat 1 12-03-2004 04:31 PM
Firewall and VPN server pilipk01 Linux - Security 2 08-26-2004 08:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration