Re: OpenBSD IPSEC VPN question
"Paul D. Robertson" <[email protected]> Tue, 30 Apr 2013 18:31:45 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
--===============0739365341== Content-Type: multipart/alternative; boundary=Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0 Content-Transfer-Encoding: 7bit --Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable I'd expect a connect() to bind implicitly to IP_ADDR_ANY and have the system= fill in the source address by default based on the destination route if the= client doesn't specify an explicit bind address and for traffic destined to= go through the VPN to do so- it sounds like it doesn't- but without more da= ta, I'd be wary of troubleshooting it (NAT, filtering...) However, I'd also advocate being able to explicitly set the bind() address t= o prevent data leakage to less-specific routes in the case of interface or r= oute failure- especially for logs. Paul -- President and Chairman, FluidIT Group Moderator, Firewall-Wizards http://pauldrobertson.net http://pauldrobertson.com @compuwar On Apr 30, 2013, at 15:56, Bennett Todd <[email protected]> wrote: > When you've got a vpn up, you're multi-homed, the Unix way for a client to= choose a network to use, when there are multiple choices, is to specify the= src ip to bind to. >=20 > I think that's the behavior I'd expect anywhere. >=20 > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><div><span></span></div><div><meta http-equ= iv=3D"content-type" content=3D"text/html; charset=3Dutf-8"><div><span></span= ></div><div><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"><div><span></span></div><div><meta http-equiv=3D"content-type" conten= t=3D"text/html; charset=3Dutf-8"><div>I'd expect a connect() to bind implici= tly to IP_ADDR_ANY and have the system fill in the source address by default= based on the destination route if the client doesn't specify an explicit bi= nd address and for traffic destined to go through the VPN to do so- it sound= s like it doesn't- but without more data, I'd be wary of troubleshooting it (= NAT, filtering...)</div><div><br></div><div>However, I'd also advocate being= able to explicitly set the bind() address to prevent data leakage to less-s= pecific routes in the case of interface or route failure- especially for log= s.<br><br>Paul<br>--<div>President and Chairman, FluidIT Group<div>Moderator= , Firewall-Wizards</div><div><a href=3D"http://pauldrobertson.net">http://pa= uldrobertson.net</a></div></div><div><a href=3D"http://pauldrobertson.com">h= ttp://pauldrobertson.com</a></div><div>@compuwar</div></div><div><br>On Apr 3= 0, 2013, at 15:56, Bennett Todd <<a href=3D"mailto:[email protected]">bet@rah= ul.net</a>> wrote:<br><br></div><blockquote type=3D"cite"><div><p dir=3D"= ltr">When you've got a vpn up, you're multi-homed, the Unix way for a client= to choose a network to use, when there are multiple choices, is to specify t= he src ip to bind to.</p> <p dir=3D"ltr">I think that's the behavior I'd expect anywhere.</p> </div></blockquote><blockquote type=3D"cite"><div><span>____________________= ___________________________</span><br><span>firewall-wizards mailing list</s= pan><br><span><a href=3D"mailto:[email protected]">fire= [email protected]</a></span><br><span><a href=3D"https://li= stserv.icsalabs.com/mailman/listinfo/firewall-wizards">https://listserv.icsa= labs.com/mailman/listinfo/firewall-wizards</a></span><br></div></blockquote>= </div></div></div></body></html>= --Apple-Mail-8B66EC16-CBC6-424E-AF8A-C98D1CC0F3E0-- --===============0739365341== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0739365341==--