SOLVED! Solaris 10 pptp/gre behind NAT

Gabriele Bulfon <[email protected]> Fri, 12 Nov 2010 09:32:37 +0100 (CET)
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <26283_1289550974_4CDCFC7D_26283_8282_1_5209026.353.1289550757979.JavaMail.root@www>
------=_Part_351_25476649.1289550757977
Content-Type: multipart/alternative; 
	boundary="----=_Part_352_31488410.1289550757977"

------=_Part_352_31488410.1289550757977
Content-type: text/plain
Content-Transfer-Encoding: 7bit

Worked like a charm!
Just update your Solaris 10 05/08 (or any, I suggest) by rebuilding sources and replacing
original ipfilter ;)
http://192.9.162.102/thread.jspa?threadID=5339408
-= Mail sent through WebTop2 =-
Da:
Gabriele Bulfon
A:
[email protected]
Data:
11 novembre 2010 13.02.40 CET
Oggetto:
Re: Confused by pptp and gre, what is the true way to do it?
After tricking with rules (modified the pass out / pass in of gre as "from any to any") now
I can see reply gre packet going out of the win machine, go through the firewall and out
of the wan to the remote machine.
Authentication fails anyway (it goes perfectly when not passint through ipfilter, both when
directly public or when passing through a zywall, but...I want it to go through ipfilter!)
How can I see if the packets are correctly masquerated?
Here are the two snoops:
-LAN interface-
remoteserverip -winlanip TCP D=4472 S=1723 Syn Ack=3520565303 Seq=1081340933 Len=0 Win=5840 Options=
remoteserverip -winlanip TCP D=4472 S=1723 Ack=3520565459 Seq=1081340934 Len=0 Win=5840
remoteserverip -winlanip TCP D=4472 S=1723 Push Ack=3520565459 Seq=1081340934 Len=156 Win=5840
remoteserverip -winlanip TCP D=4472 S=1723 Push Ack=3520565627 Seq=1081341090 Len=32 Win=6432
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49052, TOS=0x0, TTL=52
remoteserverip -winlanip TCP D=4472 S=1723 Ack=3520565651 Seq=1081341122 Len=0 Win=6432
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49053, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49054, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49055, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49056, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49057, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49058, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49059, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49060, TOS=0x0, TTL=52
remoteserverip -winlanip IP  D=winlanip S=remoteserverip LEN=61, ID=49061, TOS=0x0, TTL=52
remoteserverip -winlanip TCP D=4472 S=1723 Fin Ack=3520565651 Seq=1081341122 Len=0 Win=6432
remoteserverip -winlanip TCP D=4472 S=1723 Ack=3520565652 Seq=1081341123 Len=0 Win=6432
-WAN interface-
wanip -remoteserverip TCP D=1723 S=19463 Syn Seq=3520565302 Len=0 Win=64240 Options=
remoteserverip -wanip     TCP D=19463 S=1723 Syn Ack=3520565303 Seq=1081340933 Len=0 Win=5840 Options=
wanip -remoteserverip TCP D=1723 S=19463 Ack=1081340934 Seq=3520565303 Len=0 Win=64240
wanip -remoteserverip TCP D=1723 S=19463 Push Ack=1081340934 Seq=3520565303 Len=156 Win=64240
remoteserverip -wanip     TCP D=19463 S=1723 Ack=3520565459 Seq=1081340934 Len=0 Win=5840
remoteserverip -wanip     TCP D=19463 S=1723 Push Ack=3520565459 Seq=1081340934 Len=156 Win=5840
wanip -remoteserverip TCP D=1723 S=19463 Push Ack=1081341090 Seq=3520565459 Len=168 Win=64084
remoteserverip -wanip     TCP D=19463 S=1723 Push Ack=3520565627 Seq=1081341090 Len=32 Win=6432
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49052, TOS=0x0, TTL=53
wanip -remoteserverip TCP D=1723 S=19463 Push Ack=1081341122 Seq=3520565627 Len=24 Win=64052
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=25178, TOS=0x0, TTL=127
remoteserverip -wanip     TCP D=19463 S=1723 Ack=3520565651 Seq=1081341122 Len=0 Win=6432
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=20698, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49053, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=29457, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49054, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=9153, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49055, TOS=0x0, TTL=53
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49056, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=1984, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49057, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=671, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49058, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=14495, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49059, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=19126, TOS=0x0, TTL=127
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49060, TOS=0x0, TTL=53
remoteserverip -wanip     IP  D=wanip S=remoteserverip LEN=61, ID=49061, TOS=0x0, TTL=53
wanip -remoteserverip IP  D=remoteserverip S=wanip LEN=57, ID=5577, TOS=0x0, TTL=127
remoteserverip -wanip     TCP D=19463 S=1723 Fin Ack=3520565651 Seq=1081341122 Len=0 Win=6432
wanip -remoteserverip TCP D=1723 S=19463 Fin Ack=1081341123 Seq=3520565651 Len=0 Win=64052
remoteserverip -wanip     TCP D=19463 S=1723 Ack=3520565652 Seq=1081341123 Len=0 Win=6432
-= Mail sent through WebTop2 =-
Da:
Gabriele Bulfon
A:
[email protected]
Data:
11 novembre 2010 12.17.55 CET
Oggetto:
Re: Confused by pptp and gre, what is the true way to do it?
Hello, I investigated further the problem.
Using 2 snoops, one on each ethernet card (public and private), I can see traffic on 1732 started
by my internal win machine, the I can see the reply on that port coming to my wan, then to my lan
up to the win machine.
After, I just can see packets coming from the remote machine (stated as IP, but probably gre),
getting into the firewall and going into the lan up to the win machine.
No packet is going from the win machine on any destination.
Maybe the gre traffic is not correctly natted? Does ipfilter do masquerading on gre?
Gabriele.
-= Mail sent through WebTop2 =-
Da:
Gabriele Bulfon
A:
[email protected]
Data:
10 novembre 2010 17.02.22 CET
Oggetto:
Confused by pptp and gre, what is the true way to do it?
Hello, I've read around about how to make windows pptp vpn work behind ipfilter, but I've seen
a lot of confusion...(to me, at least).
My windows machine is in the LAN, passing through a solaris machine with ipfilter 4.1.9.
What are the general rules to let Windows pass the NAT and run the handshake?
Some talks about proxy / pptp rules mappings, some talks about just opening the ports...
I tried this but it doesn't work:
ipnat:
#NAT rules
map igb1 mylan/24 -mypubip/32 proxy port ftp ftp/tcp
map igb1 mylan/24 -mypubip/32 portmap tcp/udp 10000:40000
map igb1 mylan/24 -mypubip/32
#redirect gre to my windows machine
rdr igb1 mypubip/32 -winlanip gre
ipf:
#NAT windows machine
pass out quick on igb1 from mywinip/32 to any keep state
#Let gre enter the firewall
pass in quick on igb1 proto gre from any to mypubip/32
#Let gre pass the rdr
pass in quick on igb1 proto gre from any to winlanip/32
-= Mail sent through WebTop2 =-

------=_Part_352_31488410.1289550757977
Content-type: text/html
Content-Transfer-Encoding: quoted-printable

<div style=3D"font-family: Verdana; font-size: 12px;">Worked like a charm!<=
br>Just update your Solaris 10 05/08 (or any, I suggest) by rebuilding sour=
ces and replacing<br>original ipfilter ;)<br><br>http://192.9.162.102/threa=
d.jspa?threadID=3D5339408<br><div><br><font size=3D"1">                 -=
=3D Mail sent through WebTop2 =3D-</font>
</div><br><hr><br><br><font face=3D"Arial, Helvetica, sans-serif" size=3D"2=
"><b>Da:</b> Gabriele Bulfon &lt;[email protected]&gt;<br><b>A:</b> ipfil=
[email protected] <br><b>Data:</b> 11 novembre 2010 13.02.40 CET<br><b>=
Oggetto:</b> Re: Confused by pptp and gre, what is the true way to do it?<b=
r></font><br><br><blockquote style=3D"border-left: 2px solid rgb(0, 0, 128)=
; margin-left: 5px; padding-left: 5px;"><div style=3D"font-family: Verdana;=
 font-size: 12px;">After tricking with rules (modified the pass out / pass =
in of gre as &quot;from any to any&quot;) now<br>I can see reply gre packet=
 going out of the win machine, go through the firewall and out<br>of the wa=
n to the remote machine.<br>Authentication fails anyway (it goes perfectly =
when not passint through ipfilter, both when<br>directly public or when pas=
sing through a zywall, but...I want it to go through ipfilter!)<br><br>How =
can I see if the packets are correctly masquerated?<br>Here are the two sno=
ops:<br><br><font face=3D"courier new">-LAN interface-<br>remoteserverip -&=
gt; winlanip TCP D=3D4472 S=3D1723 Syn Ack=3D3520565303 Seq=3D1081340933 Le=
n=3D0 Win=3D5840 Options=3D&lt;mss 1460,nop,nop,sackOK&gt;<br>remoteserveri=
p -&gt; winlanip TCP D=3D4472 S=3D1723 Ack=3D3520565459 Seq=3D1081340934 Le=
n=3D0 Win=3D5840<br>remoteserverip -&gt; winlanip TCP D=3D4472 S=3D1723 Pus=
h Ack=3D3520565459 Seq=3D1081340934 Len=3D156 Win=3D5840<br>remoteserverip =
-&gt; winlanip TCP D=3D4472 S=3D1723 Push Ack=3D3520565627 Seq=3D1081341090=
 Len=3D32 Win=3D6432<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3D=
remoteserverip LEN=3D61, ID=3D49052, TOS=3D0x0, TTL=3D52<br>remoteserverip =
-&gt; winlanip TCP D=3D4472 S=3D1723 Ack=3D3520565651 Seq=3D1081341122 Len=
=3D0 Win=3D6432<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3Dremot=
eserverip LEN=3D61, ID=3D49053, TOS=3D0x0, TTL=3D52<br>remoteserverip -&gt;=
 winlanip IP  D=3Dwinlanip S=3Dremoteserverip LEN=3D61, ID=3D49054, TOS=3D0=
x0, TTL=3D52<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3Dremotese=
rverip LEN=3D61, ID=3D49055, TOS=3D0x0, TTL=3D52<br>remoteserverip -&gt; wi=
nlanip IP  D=3Dwinlanip S=3Dremoteserverip LEN=3D61, ID=3D49056, TOS=3D0x0,=
 TTL=3D52<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3Dremoteserve=
rip LEN=3D61, ID=3D49057, TOS=3D0x0, TTL=3D52<br>remoteserverip -&gt; winla=
nip IP  D=3Dwinlanip S=3Dremoteserverip LEN=3D61, ID=3D49058, TOS=3D0x0, TT=
L=3D52<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3Dremoteserverip=
 LEN=3D61, ID=3D49059, TOS=3D0x0, TTL=3D52<br>remoteserverip -&gt; winlanip=
 IP  D=3Dwinlanip S=3Dremoteserverip LEN=3D61, ID=3D49060, TOS=3D0x0, TTL=
=3D52<br>remoteserverip -&gt; winlanip IP  D=3Dwinlanip S=3Dremoteserverip =
LEN=3D61, ID=3D49061, TOS=3D0x0, TTL=3D52<br>remoteserverip -&gt; winlanip =
TCP D=3D4472 S=3D1723 Fin Ack=3D3520565651 Seq=3D1081341122 Len=3D0 Win=3D6=
432<br>remoteserverip -&gt; winlanip TCP D=3D4472 S=3D1723 Ack=3D3520565652=
 Seq=3D1081341123 Len=3D0 Win=3D6432<br></font><br><font face=3D"courier ne=
w">-WAN interface-<br>
    wanip -&gt; remoteserverip TCP D=3D1723 S=3D19463 Syn Seq=3D3520565302 =
Len=3D0 Win=3D64240 Options=3D&lt;mss 1460,nop,nop,sackOK&gt;<br>remoteserv=
erip -&gt; wanip     TCP D=3D19463 S=3D1723 Syn Ack=3D3520565303 Seq=3D1081=
340933 Len=3D0 Win=3D5840 Options=3D&lt;mss 1460,nop,nop,sackOK&gt;<br>    =
wanip -&gt; remoteserverip TCP D=3D1723 S=3D19463 Ack=3D1081340934 Seq=3D35=
20565303 Len=3D0 Win=3D64240<br>    wanip -&gt; remoteserverip TCP D=3D1723=
 S=3D19463 Push Ack=3D1081340934 Seq=3D3520565303 Len=3D156 Win=3D64240<br>=
remoteserverip -&gt; wanip     TCP D=3D19463 S=3D1723 Ack=3D3520565459 Seq=
=3D1081340934 Len=3D0 Win=3D5840<br>remoteserverip -&gt; wanip     TCP D=3D=
19463 S=3D1723 Push Ack=3D3520565459 Seq=3D1081340934 Len=3D156 Win=3D5840<=
br>    wanip -&gt; remoteserverip TCP D=3D1723 S=3D19463 Push Ack=3D1081341=
090 Seq=3D3520565459 Len=3D168 Win=3D64084<br>remoteserverip -&gt; wanip   =
  TCP D=3D19463 S=3D1723 Push Ack=3D3520565627 Seq=3D1081341090 Len=3D32 Wi=
n=3D6432<br>remoteserverip -&gt; wanip     IP  D=3Dwanip S=3Dremoteserverip=
 LEN=3D61, ID=3D49052, TOS=3D0x0, TTL=3D53<br>    wanip -&gt; remoteserveri=
p TCP D=3D1723 S=3D19463 Push Ack=3D1081341122 Seq=3D3520565627 Len=3D24 Wi=
n=3D64052<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwani=
p LEN=3D57, ID=3D25178, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip =
    TCP D=3D19463 S=3D1723 Ack=3D3520565651 Seq=3D1081341122 Len=3D0 Win=3D=
6432<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwanip LEN=
=3D57, ID=3D20698, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip     I=
P  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49053, TOS=3D0x0, TTL=3D53<b=
r>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwanip LEN=3D57,=
 ID=3D29457, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip     IP  D=
=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49054, TOS=3D0x0, TTL=3D53<br>  =
  wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwanip LEN=3D57, ID=
=3D9153, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip     IP  D=3Dwan=
ip S=3Dremoteserverip LEN=3D61, ID=3D49055, TOS=3D0x0, TTL=3D53<br>remotese=
rverip -&gt; wanip     IP  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D4905=
6, TOS=3D0x0, TTL=3D53<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserv=
erip S=3Dwanip LEN=3D57, ID=3D1984, TOS=3D0x0, TTL=3D127<br>remoteserverip =
-&gt; wanip     IP  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49057, TOS=
=3D0x0, TTL=3D53<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=
=3Dwanip LEN=3D57, ID=3D671, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; w=
anip     IP  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49058, TOS=3D0x0, =
TTL=3D53<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwanip=
 LEN=3D57, ID=3D14495, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip  =
   IP  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49059, TOS=3D0x0, TTL=3D=
53<br>    wanip -&gt; remoteserverip IP  D=3Dremoteserverip S=3Dwanip LEN=
=3D57, ID=3D19126, TOS=3D0x0, TTL=3D127<br>remoteserverip -&gt; wanip     I=
P  D=3Dwanip S=3Dremoteserverip LEN=3D61, ID=3D49060, TOS=3D0x0, TTL=3D53<b=
r>remoteserverip -&gt; wanip     IP  D=3Dwanip S=3Dremoteserverip LEN=3D61,=
 ID=3D49061, TOS=3D0x0, TTL=3D53<br>    wanip -&gt; remoteserverip IP  D=3D=
remoteserverip S=3Dwanip LEN=3D57, ID=3D5577, TOS=3D0x0, TTL=3D127<br>remot=
eserverip -&gt; wanip     TCP D=3D19463 S=3D1723 Fin Ack=3D3520565651 Seq=
=3D1081341122 Len=3D0 Win=3D6432<br>    wanip -&gt; remoteserverip TCP D=3D=
1723 S=3D19463 Fin Ack=3D1081341123 Seq=3D3520565651 Len=3D0 Win=3D64052<br=
>remoteserverip -&gt; wanip     TCP D=3D19463 S=3D1723 Ack=3D3520565652 Seq=
=3D1081341123 Len=3D0 Win=3D6432<br></font><br><div><br><font size=3D"1">  =
               -=3D Mail sent through WebTop2 =3D-</font>
</div><br><hr><br><br><font face=3D"Arial, Helvetica, sans-serif" size=3D"2=
"><b>Da:</b> Gabriele Bulfon &lt;[email protected]&gt;<br><b>A:</b> ipfil=
[email protected] <br><b>Data:</b> 11 novembre 2010 12.17.55 CET<br><b>=
Oggetto:</b> Re: Confused by pptp and gre, what is the true way to do it?<b=
r></font><br><br><blockquote style=3D"border-left: 2px solid rgb(0, 0, 128)=
; margin-left: 5px; padding-left: 5px;"><div style=3D"font-family: Verdana;=
 font-size: 12px;">Hello, I investigated further the problem.<br>Using 2 sn=
oops, one on each ethernet card (public and private), I can see traffic on =
1732 started<br>by my internal win machine, the I can see the reply on that=
 port coming to my wan, then to my lan<br>up to the win machine.<br>After, =
I just can see packets coming from the remote machine (stated as IP, but pr=
obably gre),<br>getting into the firewall and going into the lan up to the =
win machine.<br>No packet is going from the win machine on any destination.=
<br>Maybe the gre traffic is not correctly natted? Does ipfilter do masquer=
ading on gre?<br><br><br>Gabriele.<br><div><br><font size=3D"1">           =
      -=3D Mail sent through WebTop2 =3D-</font>
</div><br><hr><br><br><font face=3D"Arial, Helvetica, sans-serif" size=3D"2=
"><b>Da:</b> Gabriele Bulfon &lt;[email protected]&gt;<br><b>A:</b> ipfil=
[email protected] <br><b>Data:</b> 10 novembre 2010 17.02.22 CET<br><b>=
Oggetto:</b> Confused by pptp and gre, what is the true way to do it?<br></=
font><br><br><blockquote style=3D"border-left: 2px solid rgb(0, 0, 128); ma=
rgin-left: 5px; padding-left: 5px;"><div style=3D"font-family: Verdana; fon=
t-size: 12px;">Hello, I&#39;ve read around about how to make windows pptp v=
pn work behind ipfilter, but I&#39;ve seen<br>a lot of confusion...(to me, =
at least).<br><br>My windows machine is in the LAN, passing through a solar=
is machine with ipfilter 4.1.9.<br>What are the general rules to let Window=
s pass the NAT and run the handshake?<br>Some talks about proxy / pptp rule=
s mappings, some talks about just opening the ports...<br><br>I tried this =
but it doesn&#39;t work:<br><br>ipnat:<br><br>#NAT rules<br>map igb1 mylan/=
24 -&gt; mypubip/32 proxy port ftp ftp/tcp<br>map igb1 mylan/24 -&gt; mypub=
ip/32 portmap tcp/udp 10000:40000<br>map igb1 mylan/24 -&gt; mypubip/32<br>=
#redirect gre to my windows machine<br>rdr igb1 mypubip/32 -&gt; winlanip g=
re<br><br>ipf:<br>#NAT windows machine<br>pass out quick on igb1 from mywin=
ip/32 to any keep state<br>#Let gre enter the firewall<br>pass in quick on =
igb1 proto gre from any to mypubip/32<br>#Let gre pass the rdr<br>pass in q=
uick on igb1 proto gre from any to winlanip/32<br><div><br><font size=3D"1"=
>                 -=3D Mail sent through WebTop2 =3D-</font>
</div></div>

</blockquote></div>

</blockquote></div>

</blockquote></div>

------=_Part_352_31488410.1289550757977--

------=_Part_351_25476649.1289550757977--