Re: OpenBSD IPSEC VPN question

"Paul D. Robertson" <[email protected]> Tue, 30 Apr 2013 18:31:45 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
--===============0739365341==
Content-Type: multipart/alternative;
	boundary=Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0
Content-Transfer-Encoding: 7bit


--Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

I'd expect a connect() to bind implicitly to IP_ADDR_ANY and have the system=
 fill in the source address by default based on the destination route if the=
 client doesn't specify an explicit bind address and for traffic destined to=
 go through the VPN to do so- it sounds like it doesn't- but without more da=
ta, I'd be wary of troubleshooting it (NAT, filtering...)

However, I'd also advocate being able to explicitly set the bind() address t=
o prevent data leakage to less-specific routes in the case of interface or r=
oute failure- especially for logs.

Paul
--
President and Chairman, FluidIT Group
Moderator, Firewall-Wizards
http://pauldrobertson.net
http://pauldrobertson.com
@compuwar

On Apr 30, 2013, at 15:56, Bennett Todd <[email protected]> wrote:

> When you've got a vpn up, you're multi-homed, the Unix way for a client to=
 choose a network to use, when there are multiple choices, is to specify the=
 src ip to bind to.
>=20
> I think that's the behavior I'd expect anywhere.
>=20
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div><span></span></div><div><meta http-equ=
iv=3D"content-type" content=3D"text/html; charset=3Dutf-8"><div><span></span=
></div><div><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"><div><span></span></div><div><meta http-equiv=3D"content-type" conten=
t=3D"text/html; charset=3Dutf-8"><div>I'd expect a connect() to bind implici=
tly to IP_ADDR_ANY and have the system fill in the source address by default=
 based on the destination route if the client doesn't specify an explicit bi=
nd address and for traffic destined to go through the VPN to do so- it sound=
s like it doesn't- but without more data, I'd be wary of troubleshooting it (=
NAT, filtering...)</div><div><br></div><div>However, I'd also advocate being=
 able to explicitly set the bind() address to prevent data leakage to less-s=
pecific routes in the case of interface or route failure- especially for log=
s.<br><br>Paul<br>--<div>President and Chairman, FluidIT Group<div>Moderator=
, Firewall-Wizards</div><div><a href=3D"http://pauldrobertson.net">http://pa=
uldrobertson.net</a></div></div><div><a href=3D"http://pauldrobertson.com">h=
ttp://pauldrobertson.com</a></div><div>@compuwar</div></div><div><br>On Apr 3=
0, 2013, at 15:56, Bennett Todd &lt;<a href=3D"mailto:[email protected]">bet@rah=
ul.net</a>&gt; wrote:<br><br></div><blockquote type=3D"cite"><div><p dir=3D"=
ltr">When you've got a vpn up, you're multi-homed, the Unix way for a client=
 to choose a network to use, when there are multiple choices, is to specify t=
he src ip to bind to.</p>
<p dir=3D"ltr">I think that's the behavior I'd expect anywhere.</p>
</div></blockquote><blockquote type=3D"cite"><div><span>____________________=
___________________________</span><br><span>firewall-wizards mailing list</s=
pan><br><span><a href=3D"mailto:[email protected]">fire=
[email protected]</a></span><br><span><a href=3D"https://li=
stserv.icsalabs.com/mailman/listinfo/firewall-wizards">https://listserv.icsa=
labs.com/mailman/listinfo/firewall-wizards</a></span><br></div></blockquote>=
</div></div></div></body></html>=

--Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0--

--===============0739365341==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0739365341==--