LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-27-2005, 04:36 AM   #1
ffkodd
LQ Newbie
 
Registered: Oct 2005
Posts: 3

Rep: Reputation: 0
Allowing IPsec through NAT


Hi!

I have a suse 9.2 running and enabled with NAT/MASQUERADE.
It has two network cards:

1) External (on the internet)
2) Local Network

My computer (windows) on my LAN has no trouble accessing ANY services
on any other hosts both internally and externally.

The rules in the iptables-firewall are very simple. In effect they block all
incoming except established and related + allow everything from inside
outwards and NATs.

When I try to connect the windows-machine to the other VPN-peer I get an
indication on both the (external) VPN-box and my windows saying that IKE
handshake is ok and a tunnel is in fact up and running. The VPN-Box logs
also say that it's discovered NAT "on the other side" (my windows that is).

The problem is that I can't ping the other side even though the tunnel is up.

This leads me to think that ESP is not handled correctly by my local linux firewall.

If I connect the windows PC onto internet I have no problem at all pinging
and generally connecting to the "other side" of the VPN-peer.

Thus my question is:

What would my iptables-rules be in order to make the ESP-traffic work.

I've also read that if NAT is in the picture there will be UDP-encapsulation of
traffic. Could this be a problem?

I've read through various vpn-howtos and ipsec-howtos, trying out different
firewall rules with no success.

The involved equipment is:

Netscreen 5XP (VPN-box at work)
Windows 2000 with Netscreen software.
SuSE linux 9.2 (NAT).

Hope to hear from you guys!
 
Old 10-28-2005, 11:00 PM   #2
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
This is a general "issue" with VPN access - you need to have a static NAT for your Windows box, and permit esp and GRE to that box from outside (at least from the VPN server on the other side).
Regards,
Boris.
 
Old 10-29-2005, 02:53 AM   #3
ffkodd
LQ Newbie
 
Registered: Oct 2005
Posts: 3

Original Poster
Rep: Reputation: 0
Aha - So I have to nat ESP (and maybe AH) inwards too?

Thanks I'll give it a try!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Nat ipsec Datacenter1 Linux - Networking 0 08-25-2005 09:43 AM
IPSec Branch Office tunnel and NAT pmcdaid Linux - Networking 6 08-25-2005 05:22 AM
Blocking port 80 on NAT and allowing browsing thru squid krishvij Linux - Networking 2 07-19-2005 05:10 AM
IPSEC Tunnel behind NAT pssst_yeah_you Linux - Networking 0 06-23-2004 04:54 PM
What's the difference between Linux-NAT and Sygate-NAT? yuzuohong Linux - Networking 0 08-07-2002 04:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration