FB_security 板


I have searched google high and low for answers to this...and I have gotten many examples, howto, etc...but they all seem to have a slightly different configuration, and therefore, slightly different problems. Unfortunately, not enough of them show the network layout, along with the configuration, so it's hard to tell why certain IP are being used, and were they are on the network. I have what could be considered a fairly standard setup, and I'll bet an easy fix, but I'm just missing something. I have a single FreeBSD box that I'm setting up as a firewall / gateway / vpn for test purposes. External network: x.x.0.208/28 Internal network: y.y.1.0/24 FreeBSD 4.10-STABLE - mpd 3.19 Internal: fxp0: inet y.y.1.1 netmask 0xffffff00 broadcast y.y.1.255 External: dc0: inet x.x.0.222 netmask 0xfffffff0 broadcast x.x.0.223 Without any mpd stuff started: Destination Gateway Flags Refs Use Netif Expire default x.x.0.209 UGSc 2 15 dc0 x.x.0.208/28 link#2 UC 1 0 dc0 x.x.0.209 00:00:c5:94:ba:48 UHLW 3 0 dc0 1194 localhost localhost UH 0 0 lo0 y.y.1 link#1 UC 0 0 fxp0 Running ipfilter and ipnat, both of which work great. I have a rule set, but for testing purposes here, until I get this working, I do a pass in/out quick on all interfaces. ip.forward is on, and NAT is working. So as a firewall and gateway, I'm good, just no joy with the VPN yet. I will leave off most of the extra information about auth/crypt/compress/etc...since that whole part appears to be working just fine, I'm able to connect and authenticate. Also, for simplicity sake, assume just one VPN connection, if I get this working, I can see from the examples how to setup the rest. My first main question is in regards to putting the internal VPN connections in the same subnet as the existing internal LAN. Some people seem to, some don't. Either would be fine by me, but neither appears to work. The majority appear to just put the incoming IPs right in a range on their existing subnet, so I would assume that to be the standard method. So, let's say I want to put my incoming client at y.y.1.5, put this in my config: set ipcp ranges y.y.1.1/32 y.y.2.5/32 Now, y.y.1.1 is already the existing IP of this machine internally, and is now also going to be the termination point for the tunnel. Is this normal? It would appear to me that this could create conflict in routing. I tried making it y.y.1.2/32, no luck. Also, I wanted to make sure my external IP is in the right place, which it apepars to be, this part is working, I'm able to connect externally: set pptp self x.x.0.222 So with things setup this way, I fire it up, no errors: Jun 25 13:46:46 <daemon.info> cap mpd: [pptp0] ppp node is "mpd142-pptp0" Jun 25 13:46:46 <daemon.info> cap mpd: mpd: local IP address for PPTP is x.x.0.222 Jun 25 13:46:46 <daemon.info> cap mpd: [pptp0] using interface ng0 And as I would expect, ifconfig now shows the new netgraph interface, there are no changes to the routing table. ng0: flags=8890<POINTOPOINT,NOARP,SIMPLEX,MULTICAST> mtu 1500 I then connect my client, after all the authentication goes by without error, it leaves with: Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] IPCP: LayerUp Jun 25 13:48:47 <daemon.info> cap mpd: y.y.1.1 -> y.y.1.5 Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] IFACE: Up event Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] setting interface ng0 MTU to 1196 bytes Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] exec: /sbin/ifconfig ng0 y.y.1.1 y.y.1.5 netmask 0xffffffff -link0 Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] exec: /sbin/route add y.y.1.1 -iface lo0 Jun 25 13:48:47 <daemon.info> cap mpd: [pptp0] IFACE: Up event And my route table now has this added on: y.y.1.1 lo0 UHS 0 0 lo0 y.y.1.5 192.168.1.1 UH 0 0 ng0 and ifconfig gives me: inet y.y.1.1 --> y.y.1.5 netmask 0xffffffff The first thing that jumps out at me here...lo0 as the interface!?!? That seems strange, but I don't see how to control this. >From my client, I can ping y.y.1.5, but not y.y.1.1, so it's not getting anything back from the other end of the tunnel. And from the server, I can of course still ping y.y.1.1, but not y.y.1.5, it gives: ping: sendto: No route to host. Now, this all seems to make sense to me, as to why it's doing what it's doing. But I don't know how to tell it to do what I want! I have played around with static routes and the arp proxy stuff, to no avail. I have tried moving the VPN clients to a different internal subnet, y.y.2.0/24, and got different results, but pretty much what I would have expected. Any help in this matter would be GREATLY appreciated! -Daniel _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "[email protected]"







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草
伺服器連線錯誤,造成您的不便還請多多包涵!
「贊助商連結」






like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:BabyMother站內搜尋

TOP