Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: INET_IFACE: Secure to allow traffic from 192.168.x.0/24?
Date: Fri, 5 Mar 2004 01:29:54 +0000	[thread overview]
Message-ID: <200403050129.54915.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <40472125.4000608@blinkenlichten.de>

On Thursday 04 March 2004 12:29 pm, Carsten Maass wrote:

> Dear List,
>
> recently i connected together two internal networks over an IPSec-tunnel:
>
> (Localnet A)---(Gateway A)==IPSec==(Gateway B)---(Localnet B)

How did you set up IPsec?   Using FreeS/WAN and Linux kernel 2.4.x?   Using 
the new built-in IPsec in kernel 2.6.x?   Some other method?   It makes a big 
difference to what you can filter, and how netfilter sees the packets.

Also, do you have one machine at each end of the link which is both running 
netfilter and acting as the IPsec gateway, or do you have two different 
machines, one doing netfilter, and one doing IPsec?

> Now i am unsure which iptables-rules i should apply to the external
> interfaces of the gateways to match the traffic between the Localnets
> without opening up a security hole. Is it sufficient to simply apply
> some general rules like:
>
> $IPTABLES -A FORWARD -i $INET_IFACE -s 192.168.a.0/24 -j ACCEPT
> $IPTABLES -A FORWARD -i $INET_IFACE -s 192.168.b.0/24 -j ACCEPT
>
> or would this approach be vulnerable to some kind of IP-spoofing attack?

If you are using FreeS/WAN and Linux 2.4.x you can filter real packets going 
to & from the "ipsecN" interfaces, and you can filter ESP packets going in 
and out of the "ethN" interfaces.   Tell us the details and I'll suggest 
something more specific if I can.

Regards,

Antony.

-- 
Having been asked for a reference for this man,
I can confirm that you will be very lucky indeed if you can get him to work 
for you.

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-03-05  1:29 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-03-04 12:29 INET_IFACE: Secure to allow traffic from 192.168.x.0/24? Carsten Maass
2004-03-05  1:29 ` Antony Stone [this message]
2004-03-05 11:28   ` Carsten Maass
2004-03-05 11:40     ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200403050129.54915.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox