From mboxrd@z Thu Jan 1 00:00:00 1970 From: "John Paul" Subject: Problem Found! - Firewall Rule Date: Fri, 6 Jun 2003 07:56:08 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <012001c32bbe$08915a30$fd00a8c0@homes> Reply-To: "John Paul" Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_011D_01C32C01.1689B9A0" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_011D_01C32C01.1689B9A0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello Folks, its me again :( Below is my config. My problem is, I can connect to VPN but for some = reason, I cannot see machines inside the network after being connected. = Can somebody give me the simpliest firewall rule on this? just for me to = see the machines inside the network. Thanks! /JP PC1 (192.168.0.20) ----> gateway(LinuxServer) <-------------------> = internet <--------------------> VPN Server eth0 : 1.1.1.1 = eth0 : 2.2.2.2 eth1 : 192.168.0.1 = local ip: 192.168.0.10 = remote ip: = 192.168.0.180-200 =20 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ PC1 is already connected to the VPN server. PC1 ip now becomes; Ethernet adapter Local Area Connection: Connection-specific DNS Suffix . :=20 IP Address. . . . . . . . . . . . : 192.168.0.253 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.0.10 PPP adapter Sytes.Net: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : 192.168.0.180 Subnet Mask . . . . . . . . . . . : 255.255.255.255 Default Gateway . . . . . . . . . : 192.168.0.180 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ route -n Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use = Iface 202.163.246.1 0.0.0.0 255.255.255.255 UH 0 0 0 = ppp0 192.168.0.180 0.0.0.0 255.255.255.255 UH 0 0 0 = ppp1 192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 = eth0 127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 = lo 0.0.0.0 202.163.246.1 0.0.0.0 UG 0 0 0 = ppp0 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ ------=_NextPart_000_011D_01C32C01.1689B9A0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello Folks, its me again = :(
 
Below is my config. My problem is, I can connect to VPN but for = some=20 reason, I cannot see machines inside the network after being connected. = Can=20 somebody give me the simpliest firewall rule on this? just for = me to=20 see the machines inside the network.
 
Thanks!
/JP
 
 
 
PC1 (192.168.0.20) ---->=20 gateway(LinuxServer) <-------------------> internet=20 <--------------------> VPN Server
       =20             =    =20            eth0=20 : 1.1.1.1          = ;            =             &= nbsp;           &n= bsp;           &nb= sp;           &nbs= p;=20 eth0 : 2.2.2.2
          &nbs= p;            = ;            = eth1=20 :=20 192.168.0.1          &n= bsp;           &nb= sp;           &nbs= p;            = ;            =       local=20 ip: 192.168.0.10
            =    =20             =    =20             =    =20             =    =20             =    =20             =    =20             =    =20             =   remote ip:=20 192.168.0.180-200 
 
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
 
PC1 is already connected to the VPN=20 server. PC1 ip now becomes;
 
Ethernet adapter Local Area=20 Connection:
 
       =20 Connection-specific DNS Suffix  . : 
        IP=20 Address. . . . . . . . . . . . :=20 192.168.0.253
        Subnet Mask = . . . .=20 . . . . . . . : = 255.255.255.0
       =20 Default Gateway . . . . . . . . . : 192.168.0.10
 
PPP adapter Sytes.Net:
 
       =20 Connection-specific DNS Suffix  .=20 :
        IP Address. . . . . . . = . . . .=20 . : 192.168.0.180
        Subnet = Mask . .=20 . . . . . . . . . :=20 255.255.255.255
        Default = Gateway .=20 . . . . . . . . : 192.168.0.180
 
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
 
route -n
 
Kernel IP routing table
Destination    =20 Gateway        =20 Genmask         Flags Metric=20 Ref    Use Iface
202.163.246.1  =20 0.0.0.0         255.255.255.255=20 UH    0     =20 0        0 = ppp0
192.168.0.180  =20 0.0.0.0         255.255.255.255=20 UH    0     =20 0        0=20 ppp1
192.168.0.0    =20 0.0.0.0        =20 255.255.255.0   U    =20 0      = 0        0=20 eth0
127.0.0.0      =20 0.0.0.0        =20 255.0.0.0       U    =20 0      = 0        0=20 lo
0.0.0.0        =20 202.163.246.1  =20 0.0.0.0         = UG   =20 0      = 0        0=20 ppp0
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
------=_NextPart_000_011D_01C32C01.1689B9A0-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "George Vieira" Subject: RE: Problem Found! - Firewall Rule Date: Fri, 6 Jun 2003 10:56:18 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C32BC6.70390F54" Return-path: content-class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: John Paul , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C32BC6.70390F54 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Your local IP is the same as the remote networks IP.. so how is the = local machine to know that 192.168.0.55 or 66 or 32 is on the VPN!? =20 The only way I know is to proxyarp the ppp device that the vpn is = running on.. I'm assuming it's PPTP so you could try this command when = the VPN comes up : echo 1 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp =20 and this must be done on the VPN server too.. I've never done it this way with a VPN.. but you can only try it.. =20 I'm surprised that anything really works properly the way you've done it = because the firewall has 2 network devices with the same IP range. Thanks, =20 ____________________________________________ George Vieira Citadel Computer Systems Pty Ltd Systems Manager georgev AT = citadelcomputer DOT com DOT au=20 Citadel Computer Systems Pty Ltd Phone : +61 2 9955 2644 HelpDesk: +61 2 9955 2698 = http://www.citadelcomputer.com.au =20 =20 -----Original Message----- From: John Paul [mailto:john@pinoylinux.sytes.net] Sent: Friday, June 06, 2003 9:56 AM To: netfilter@lists.netfilter.org Subject: Problem Found! - Firewall Rule Hello Folks, its me again :( =20 Below is my config. My problem is, I can connect to VPN but for some = reason, I cannot see machines inside the network after being connected. = Can somebody give me the simpliest firewall rule on this? just for me to = see the machines inside the network. =20 Thanks! /JP =20 ------_=_NextPart_001_01C32BC6.70390F54 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Your=20 local IP is the same as the remote networks IP.. so how is the local = machine to=20 know that 192.168.0.55 or 66 or 32 is on the VPN!?
 
The=20 only way I know is to proxyarp the ppp device that the vpn is running = on.. I'm=20 assuming it's PPTP so you could try this command when the VPN comes up=20 :
echo 1=20 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp
 
and this must be done on the = VPN server=20 too..
I've=20 never done it this way with a VPN.. but you can only try=20 it..
 
I'm=20 surprised that anything really works properly the way you've done it = because the=20 firewall has 2 network devices with the same IP = range.

Thanks,

 
____________________________________________George=20 Vieira
Citadel=20 Computer Systems Pty Ltd Systems=20 Manager georgev AT=20 citadelcomputer DOT com DOT au
Citadel Computer Systems Pty Ltd
Phone : +61 2 9955=20 2644 HelpDesk: +61 2 9955=20 2698 http://www.citadelcomputer.co= m.au
 
 
-----Original Message-----
From: John Paul=20 [mailto:john@pinoylinux.sytes.net]
Sent: Friday, June 06, 2003 = 9:56=20 AM
To: netfilter@lists.netfilter.org
Subject: = Problem Found!=20 - Firewall Rule

Hello Folks, its me again = :(
 
Below is my config. My problem is, I can connect to VPN but for = some=20 reason, I cannot see machines inside the network after being connected. = Can=20 somebody give me the simpliest firewall rule on this? just for = me to=20 see the machines inside the network.
 
Thanks!
/JP
 
------_=_NextPart_001_01C32BC6.70390F54-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ray Leach Subject: RE: Problem Found! - Firewall Rule Date: 06 Jun 2003 08:52:28 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1054882347.13616.53.camel@raylinux.internal> References: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-VK1+HYtcCLq6dmBa7I8x" Return-path: In-Reply-To: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Netfilter Mailing List --=-VK1+HYtcCLq6dmBa7I8x Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Fri, 2003-06-06 at 02:56, George Vieira wrote: > Your local IP is the same as the remote networks IP.. so how is the > local machine to know that 192.168.0.55 or 66 or 32 is on the VPN!? > =20 > The only way I know is to proxyarp the ppp device that the vpn is > running on.. I'm assuming it's PPTP so you could try this command when > the VPN comes up : > echo 1 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp You can also use the netfilter P-O-M route patch, which allows you to redirect traffic via different interfaces (route) based on regular iptables conditions (-s, -d, -p, etc). > =20 > and this must be done on the VPN server too.. > I've never done it this way with a VPN.. but you can only try it.. > =20 > I'm surprised that anything really works properly the way you've done > it because the firewall has 2 network devices with the same IP range. >=20 > Thanks, >=20 >=20 > =20 > ____________________________________________ > George Vieira > Citadel Computer Systems Pty Ltd Systems Managergeorgev AT > citadelcomputer DOT com DOT au > Citadel Computer Systems Pty Ltd > Phone : +61 2 9955 2644HelpDesk: +61 2 9955 2698 > http://www.citadelcomputer.com.au > =20 > =20 > -----Original Message----- > From: John Paul [mailto:john@pinoylinux.sytes.net] > Sent: Friday, June 06, 2003 9:56 AM > To: netfilter@lists.netfilter.org > Subject: Problem Found! - Firewall Rule >=20 >=20 > Hello Folks, its me again :( > =20 > Below is my config. My problem is, I can connect to VPN but for some > reason, I cannot see machines inside the network after being > connected. Can somebody give me the simpliest firewall rule on this? > just for me to see the machines inside the network. > =20 > Thanks! > /JP > =20 --=20 -- Raymond Leach Network Support Specialist http://www.knowledgefactory.co.za "lynx -source http://www.rchq.co.za/raymondl.asc | gpg --import" Key fingerprint =3D 7209 A695 9EE0 E971 A9AD 00EE 8757 EE47 F06F FB28 -- --=-VK1+HYtcCLq6dmBa7I8x Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQA+4Dorh1fuR/Bv+ygRAuE9AKC7AxQoZo829JhTnkXAi0AvCiyOmgCfcxWC 9NqHE8n8qMAAxYTAbXmFN5M= =rllM -----END PGP SIGNATURE----- --=-VK1+HYtcCLq6dmBa7I8x-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "loong" Subject: firewall bridge , Vlan ? Date: Mon, 9 Jun 2003 11:46:59 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <039a01c32e39$ce5ab310$b401a8c0@ows5> References: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> <005c01c32e38$380565f0$1500a8c0@expi> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0396_01C32E7C.D5CB78D0" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0396_01C32E7C.D5CB78D0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable hi is there anywhere install bridge firewall and install vlan http://www.candelatech.com/~greear/vlan.html so that my firewall can run like netscreen without using hug or switch = to my webserver. currently is internet -- > eth0 firewall eth1 -- > hub ------> webserver 1 ------> webserver 2 is that anywhere i install few network card in my firewall then internet ---> eth0 firewall eth1 ----> webserver 1 eth2 -----> = webserver 2 eth3 -----> = webserver 3 thanks loong ----- Original Message -----=20 From: John Paul=20 To: George Vieira ; netfilter@lists.netfilter.org=20 Sent: Monday, June 09, 2003 11:35 AM Subject: Re: Problem Found! - Firewall Rule Thanks George. I have modified my network to (10.10.0.0/24).=20 Now, I'am able to ping the machines inside the network after connected = to the VPN. The problem now is, I'm not able to map/see machines in = Network Neighborhood except the VPN server. Any clue? =20 ----- Original Message -----=20 From: George Vieira=20 To: John Paul ; netfilter@lists.netfilter.org=20 Sent: Friday, June 06, 2003 8:56 AM Subject: RE: Problem Found! - Firewall Rule Your local IP is the same as the remote networks IP.. so how is the = local machine to know that 192.168.0.55 or 66 or 32 is on the VPN!? The only way I know is to proxyarp the ppp device that the vpn is = running on.. I'm assuming it's PPTP so you could try this command when = the VPN comes up : echo 1 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp and this must be done on the VPN server too.. I've never done it this way with a VPN.. but you can only try it.. I'm surprised that anything really works properly the way you've = done it because the firewall has 2 network devices with the same IP = range. Thanks, ____________________________________________ George Vieira Citadel Computer Systems Pty LtdSystems Managergeorgev AT = citadelcomputer DOT com DOT au Citadel Computer Systems Pty Ltd Phone : +61 2 9955 2644HelpDesk: +61 2 9955 = 2698http://www.citadelcomputer.com.au -----Original Message----- From: John Paul [mailto:john@pinoylinux.sytes.net] Sent: Friday, June 06, 2003 9:56 AM To: netfilter@lists.netfilter.org Subject: Problem Found! - Firewall Rule Hello Folks, its me again :( Below is my config. My problem is, I can connect to VPN but for some = reason, I cannot see machines inside the network after being connected. = Can somebody give me the simpliest firewall rule on this? just for me to = see the machines inside the network. Thanks! /JP ------=_NextPart_000_0396_01C32E7C.D5CB78D0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
hi
 
is there anywhere install bridge firewall and = install=20 vlan
http://www.candelat= ech.com/~greear/vlan.html
 
 
so that my firewall can run like netscreen without = using =20 hug or switch to my webserver.
 
currently is
internet -- > eth0 firewall   = eth1 --=20 >   hub ------> webserver 1
          &nbs= p;            = ;            =             &= nbsp;    =20 ------> webserver 2
 
is that anywhere i install few network card in my = firewall=20 then
 
internet = --->    eth0   =20 firewall   eth1 ---->    webserver = 1
          &nbs= p;            = ;            =             &= nbsp;    =20 eth2 ----->   webserver 2
          &nbs= p;            = ;            =             &= nbsp;     eth3=20 ----->  webserver 3
 
 
thanks
 
loong
 
 
 
 
 
 
 
 
 
----- Original Message -----
From:=20 John Paul
To: George Vieira ; netfilter@lists.netfilter.o= rg=20
Sent: Monday, June 09, 2003 = 11:35=20 AM
Subject: Re: Problem Found! - = Firewall=20 Rule

Thanks George. I have modified my = network to=20 (10.10.0.0/24).
 
Now, I'am able to ping the machines = inside the=20 network after connected to the VPN. The problem now is, I'm not able = to=20 map/see machines in Network Neighborhood except the VPN = server.
 
Any clue?      
 
 
----- Original Message -----
From:=20 George Vieira =
To: John Paul ; netfilter@lists.netfilter.o= rg=20
Sent: Friday, June 06, 2003 = 8:56=20 AM
Subject: RE: Problem Found! - = Firewall=20 Rule

Your local IP is the same as the remote networks IP.. so = how is the=20 local machine to know that 192.168.0.55 or 66 or 32 is on the=20 VPN!?
 
The only way I know is to proxyarp the ppp device that the = vpn is=20 running on.. I'm assuming it's PPTP so you could try this command = when the=20 VPN comes up :
echo 1 >=20 /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp
 
and this must be done on = the VPN=20 server too..
I've never done it this way with a VPN.. = but you=20 can only try it..
 
I'm surprised that anything really works = properly=20 the way you've done it because the firewall has 2 network devices = with the=20 same IP range.

Thanks,

 
____________________________________________George=20 Vieira
Citadel=20 Computer Systems Pty Ltd Systems=20 Manager georgev=20 AT citadelcomputer DOT com DOT au
Citadel Computer Systems Pty Ltd
Phone : +61 2 9955=20 2644 HelpDesk: +61 2 9955=20 2698 http://www.citadelcomputer.co= m.au
 
 
-----Original Message-----
From: John Paul=20 [mailto:john@pinoylinux.sytes.net]
Sent: Friday, June 06, = 2003=20 9:56 AM
To: = netfilter@lists.netfilter.org
Subject:=20 Problem Found! - Firewall Rule

Hello Folks, its me again = :(
 
Below is my config. My problem is, I can connect to VPN but for = some=20 reason, I cannot see machines inside the network after being = connected. Can=20 somebody give me the simpliest firewall rule on this? just = for me=20 to see the machines inside the network.
 
Thanks!
/JP
 
------=_NextPart_000_0396_01C32E7C.D5CB78D0-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "George Vieira" Subject: RE: Problem Found! - Firewall Rule Date: Mon, 9 Jun 2003 14:22:03 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <09B04A55822EFF4DA48D2E0BB2941D4A019269@wardrive.citadelcomputer.com.au> Mime-Version: 1.0 Content-Transfer-Encoding: base64 Return-path: content-class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: John Paul , netfilter@lists.netfilter.org VGhlIG9ubHkgc29sdXRpb24gdG8gdGhpcyBpcyB0byBtYWtlIHRoZSBWUE4gc2VydmVyIG9yIHRo ZSBvdGhlciBuZXR3b3JrIGJlIHRoZSBtYXN0ZXIgYnJvd3NlciBvZiB0aGF0IG5ldHdvcmsuLiBz byBpdCBoYW5kbGVzIGFsbCB0aGUgbmV0YmlvcyBicm9hZGNhc3RzIGFuZCBhbGwuDQogDQpPbmNl IHRoaXMgaXMgZG9uZSwgc2V0dXAgc2FtYmEgb24gdGhlIHJlbW90ZSBmaXJld2FsbCB0byBkbyBh ICJyZW1vdGUgYW5ub3VuY2UgPSAxMC4xMC4yNTUuMjU1IiBvbnRvIHlvdXIgbmV0d29yay4uLiBz b21ldGhpbmcgbGlrZSB0aGF0Li4gaXQncyBiZWVuIGEgd2hpbGUgc2luY2UgSSd2ZSBkb25lIHRo aXMuLg0KIA0KVGhvdWdoIHRoaXMgbXVzdCBiZSB0aGUgVlBOIHNlcnZlciB0aGF0IHJ1bnMgdGhl IG1hc3RlciBicm93c2VyIGJlY2F1c2UgYnJvYWRjYXN0cyBETyBOT1QgUk9VVEUgc28gaXQgY2Fu J3QgYmUgZG9uZSB3aXRoIGEgc2VydmVyIGluc2lkZSB0aGUgVlBOIHNlcnZlcnMgbmV0d29yay4u DQogDQpnaXZlIHRoYXQgYSB0cnkuIHN0YXRpYyBtYXBwaW5ncyBzaG91bGQgd29yayB0aG91Z2gg YXMgbG9uZyBhcyB5b3Uga25vdyB3aGF0IHlvdXIgbG9va2luZyBmb3IuDQogDQoNCgktLS0tLU9y aWdpbmFsIE1lc3NhZ2UtLS0tLSANCglGcm9tOiBKb2huIFBhdWwgW21haWx0bzpqb2huQHBpbm95 bGludXguc3l0ZXMubmV0XSANCglTZW50OiBNb24gMDktSnVuLTAzIDE6MzUgUE0gDQoJVG86IEdl b3JnZSBWaWVpcmE7IG5ldGZpbHRlckBsaXN0cy5uZXRmaWx0ZXIub3JnIA0KCUNjOiANCglTdWJq ZWN0OiBSZTogUHJvYmxlbSBGb3VuZCEgLSBGaXJld2FsbCBSdWxlDQoJDQoJDQoJIA0KDQo= From mboxrd@z Thu Jan 1 00:00:00 1970 From: "John Paul" Subject: Re: Problem Found! - Firewall Rule Date: Mon, 9 Jun 2003 11:35:46 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <005c01c32e38$380565f0$1500a8c0@expi> References: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0059_01C32E7B.448A8650" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: George Vieira , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0059_01C32E7B.448A8650 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Thanks George. I have modified my network to (10.10.0.0/24).=20 Now, I'am able to ping the machines inside the network after connected = to the VPN. The problem now is, I'm not able to map/see machines in = Network Neighborhood except the VPN server. Any clue? =20 ----- Original Message -----=20 From: George Vieira=20 To: John Paul ; netfilter@lists.netfilter.org=20 Sent: Friday, June 06, 2003 8:56 AM Subject: RE: Problem Found! - Firewall Rule Your local IP is the same as the remote networks IP.. so how is the = local machine to know that 192.168.0.55 or 66 or 32 is on the VPN!? The only way I know is to proxyarp the ppp device that the vpn is = running on.. I'm assuming it's PPTP so you could try this command when = the VPN comes up : echo 1 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp and this must be done on the VPN server too.. I've never done it this way with a VPN.. but you can only try it.. I'm surprised that anything really works properly the way you've done = it because the firewall has 2 network devices with the same IP range. Thanks, ____________________________________________ George Vieira Citadel Computer Systems Pty LtdSystems Managergeorgev AT = citadelcomputer DOT com DOT au Citadel Computer Systems Pty Ltd Phone : +61 2 9955 2644HelpDesk: +61 2 9955 = 2698http://www.citadelcomputer.com.au -----Original Message----- From: John Paul [mailto:john@pinoylinux.sytes.net] Sent: Friday, June 06, 2003 9:56 AM To: netfilter@lists.netfilter.org Subject: Problem Found! - Firewall Rule Hello Folks, its me again :( Below is my config. My problem is, I can connect to VPN but for some = reason, I cannot see machines inside the network after being connected. = Can somebody give me the simpliest firewall rule on this? just for me to = see the machines inside the network. Thanks! /JP ------=_NextPart_000_0059_01C32E7B.448A8650 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Thanks George. I have modified my = network to=20 (10.10.0.0/24).
 
Now, I'am able to ping the machines = inside the=20 network after connected to the VPN. The problem now is, I'm not able to = map/see=20 machines in Network Neighborhood except the VPN server.
 
Any clue?      
 
 
----- Original Message -----
From:=20 George Vieira =
To: John Paul ; netfilter@lists.netfilter.o= rg=20
Sent: Friday, June 06, 2003 = 8:56 AM
Subject: RE: Problem Found! - = Firewall=20 Rule

Your=20 local IP is the same as the remote networks IP.. so how is the local = machine=20 to know that 192.168.0.55 or 66 or 32 is on the = VPN!?
 
The=20 only way I know is to proxyarp the ppp device that the vpn is running = on.. I'm=20 assuming it's PPTP so you could try this command when the VPN comes up = :
echo=20 1 > /proc/sys/net/ipv4/conf/$VPNDEV/proxy_arp
 
and this must be done on the = VPN server=20 too..
I've=20 never done it this way with a VPN.. but you can only try=20 it..
 
I'm=20 surprised that anything really works properly the way you've done it = because=20 the firewall has 2 network devices with the same IP = range.

Thanks,

 
____________________________________________George=20 Vieira
Citadel=20 Computer Systems Pty Ltd Systems=20 Manager georgev AT=20 citadelcomputer DOT com DOT au
Citadel Computer Systems Pty Ltd
Phone : +61 2 9955=20 2644 HelpDesk: +61 2 9955=20 2698 http://www.citadelcomputer.co= m.au
 
 
-----Original Message-----
From: John Paul=20 [mailto:john@pinoylinux.sytes.net]
Sent: Friday, June 06, = 2003 9:56=20 AM
To: netfilter@lists.netfilter.org
Subject: = Problem=20 Found! - Firewall Rule

Hello Folks, its me again = :(
 
Below is my config. My problem is, I can connect to VPN but for = some=20 reason, I cannot see machines inside the network after being = connected. Can=20 somebody give me the simpliest firewall rule on this? just = for me to=20 see the machines inside the network.
 
Thanks!
/JP
 
------=_NextPart_000_0059_01C32E7B.448A8650-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Cedric Blancher Subject: Re: firewall bridge , Vlan ? Date: 09 Jun 2003 12:08:26 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1055153305.648.12.camel@elendil.intranet.cartel-securite.net> References: <09B04A55822EFF4DA48D2E0BB2941D4A019266@wardrive.citadelcomputer.com.au> <005c01c32e38$380565f0$1500a8c0@expi> <039a01c32e39$ce5ab310$b401a8c0@ows5> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <039a01c32e39$ce5ab310$b401a8c0@ows5> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: loong Cc: netfilter@lists.netfilter.org Le lun 09/06/2003 =E0 05:46, loong a =E9crit : > is there anywhere install bridge firewall and install vlan > http://www.candelatech.com/~greear/vlan.html This works very well. =20 > so that my firewall can run like netscreen without using hug or > switch to my webserver. You'll still have to use at leat one switch. =20 > currently is > internet -- > eth0 firewall eth1 -- > hub ------> webserver 1 > ------> webserver > 2 > =20 > is that anywhere i install few network card in my firewall then > =20 > internet ---> eth0 firewall eth1 ----> webserver 1 > eth2 -----> =20 > webserver 2 > eth3 ----->=20 > webserver 3 Your physical setup will be like this : Internet -> eth0/Firewall/eth1 -> switch -> Web1 -> Web2 You can also have : Firewall/eth0 -> switch -> Internet -> Web1 -> Web2 But I don't recommand this setup as it relies too much on switch security features. So, you connect eth1 to your switch. This switch must support VLAN and 802.1q frame tagging. On the switch, configure the port connected to eth0 as a 802.1q port (called trunk on Cisco). Now, affect one VLAN to Web1 port, and another one to Web2 port, etc... Eth0's port will carry all affected VLANs (see you switch documentation). Now, on your firewall, use vconfig to create virtual interfaces associated to each VLAN you want to see through the 802.1q link. Suppose Web1 is on VLAN1, Web2 on VLAN2 : vconfig add eth0 1 vconfig add eth0 2 This will create vlan0001 and vlan0002 interfaces trhough which you'll see respectively Web1's traffic and Web2's traffic. See vconfig man page for further information. Now, this solution is very scalable as you can add as many VLAN as you want on your switch. You just have to add them to the 802.1q link and create proper interface on the firewall. Then you configure your routing and filtering between those vlan* interfaces just you way you're use to between physical ones (eth*). Note that eth1 will see 802.1q tagged frames. But beware to the fact that this kind of network separation directly depends on your switch security. If one is able to gain access to the switch or find a way to bypass it, you loose everything relying on VLANs. See : http://www.arp-sk.org/doc/bh-us-02-convrey-switches.pdf --=20 C=E9dric Blancher IT systems and networks security - Cartel S=E9curit=E9 Phone : +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99 PGP KeyID:157E98EE FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE