* RE: IPSec rules
2003-03-28 15:52 IPSec rules James Miller
@ 2001-03-28 16:57 ` Rowan Reid
2003-03-28 16:45 ` Cedric Blancher
1 sibling, 0 replies; 3+ messages in thread
From: Rowan Reid @ 2001-03-28 16:57 UTC (permalink / raw)
To: jimm, netfilter
ce of IPSec traffic. eth1 = untrusted side eth0 = trusted side
>
> INPUT:
> $IPTABLES -A INPUT -i eth1 -p 50 -j ACCEPT
> $IPTABLES -A INPUT -i eth1 -p 51 -j ACCEPT
> $IPTABLES -A INPUT -i eth1 -p UDP --dport 500 -j ACCEPT
>
> FORWARD:
> $IPTABLES -A FORWARD -i eth0 -o ipsec+ -j ACCEPT
> $IPTABLES -A FORWARD -i ipsec+ -o eth0 -j ACCEPT
>
> OUTPUT:
> $IPTABLES -A OUTPUT -p 50 -j ACCEPT
> $IPTABLES -A OUTPUT -p 51 -j ACCEPT
> $IPTABLES -A INPUT -p udp -m udp --dport 500 -j ACCEPT
Looks good that’s pretty much what I have. 'cept I actually specify ah
and eps for my protocol. Don’t forget not to masquarade outgoing
packates through your vpn. Since I have a net to net connection that is
fairly definate I only allow connections from my trusted hosts.
^ permalink raw reply [flat|nested] 3+ messages in thread
* IPSec rules
@ 2003-03-28 15:52 James Miller
2001-03-28 16:57 ` Rowan Reid
2003-03-28 16:45 ` Cedric Blancher
0 siblings, 2 replies; 3+ messages in thread
From: James Miller @ 2003-03-28 15:52 UTC (permalink / raw)
To: netfilter
Hello everyone =)
I have reviewed a few posts about how to setup rules to allow IPSec. I sure
would appreciate a peer review of my rules for IPSec traffic before putting
them into general use. Of course, this is not my whole rule set, just the
IPSec aspects. I'm not doing NAT on the inside (we're lucky enough to have
a few class 'C's to use around here). And for simplicity I'm trusting
roadwarriors and not limiting the source of IPSec traffic.
eth1 = untrusted side
eth0 = trusted side
INPUT:
$IPTABLES -A INPUT -i eth1 -p 50 -j ACCEPT
$IPTABLES -A INPUT -i eth1 -p 51 -j ACCEPT
$IPTABLES -A INPUT -i eth1 -p UDP --dport 500 -j ACCEPT
FORWARD:
$IPTABLES -A FORWARD -i eth0 -o ipsec+ -j ACCEPT
$IPTABLES -A FORWARD -i ipsec+ -o eth0 -j ACCEPT
OUTPUT:
$IPTABLES -A OUTPUT -p 50 -j ACCEPT
$IPTABLES -A OUTPUT -p 51 -j ACCEPT
$IPTABLES -A INPUT -p udp -m udp --dport 500 -j ACCEPT
Thanks everyone,
--jim
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: IPSec rules
2003-03-28 15:52 IPSec rules James Miller
2001-03-28 16:57 ` Rowan Reid
@ 2003-03-28 16:45 ` Cedric Blancher
1 sibling, 0 replies; 3+ messages in thread
From: Cedric Blancher @ 2003-03-28 16:45 UTC (permalink / raw)
To: jimm; +Cc: netfilter
Le ven 28/03/2003 à 16:52, James Miller a écrit :
> I have reviewed a few posts about how to setup rules to allow IPSec. I sure
> would appreciate a peer review of my rules for IPSec traffic before putting
> them into general use.
[...]
> INPUT:
> $IPTABLES -A INPUT -i eth1 -p 50 -j ACCEPT
> $IPTABLES -A INPUT -i eth1 -p 51 -j ACCEPT
> $IPTABLES -A INPUT -i eth1 -p UDP --dport 500 -j ACCEPT
You can harden this one saying source port has also to be 500.
[...]
> OUTPUT:
> $IPTABLES -A OUTPUT -p 50 -j ACCEPT
> $IPTABLES -A OUTPUT -p 51 -j ACCEPT
> $IPTABLES -A INPUT -p udp -m udp --dport 500 -j ACCEPT
You can also add output interface using "-o eth1" and specify source
port for last rule.
Matching state is not useful if both sides are likely to initiate IPSEC
tunnel.
--
Cédric Blancher <blancher@cartel-securite.fr>
IT systems and networks security - Cartel Sécurité
Phone : +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99
PGP KeyID:157E98EE FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2003-03-28 16:45 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-28 15:52 IPSec rules James Miller
2001-03-28 16:57 ` Rowan Reid
2003-03-28 16:45 ` Cedric Blancher
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox