IPsec with 1:1 NAT
Reinhard Vicinus via Shorewall-users <[email protected]> Mon, 19 May 2025 06:39:06 +0000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Organization | Metaways Infosystems GmbH |
| Message-ID | <[email protected]> |
--===============0868526779440321712==
Content-Type: multipart/alternative;
boundary="=_4cd2eccb8c6fe0a9802f9b5e31f59b32"
--=_4cd2eccb8c6fe0a9802f9b5e31f59b32
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
I am trying to get an 1:1 NAT configured prior to sending the packages i=
nto an IPsec tunnel, but as far as I can tell the NAT is never applied a=
nd the packages also never get into the tunnel.=0A=0AThe IPsec tunnel co=
nfiguration:=0A=0Aconn rz2trz1=0A=C2=A0 auto=3Droute=0A=C2=A0 closeactio=
n=3Drestart=0A=C2=A0 esp=3Daes256-sha256-ecp384=0A=C2=A0 ike=3Daes256-sh=
a256-ecp384=0A=C2=A0 ikelifetime=3D60m=0A=C2=A0 keyexchange=3Dikev2=0A=
=C2=A0 left=3D192.0.2.1=0A=C2=A0 leftauth=3Dpsk=0A=C2=A0 leftsubnet=3D10=
.192.2.0/24=0A=C2=A0 lifetime=3D30m=0A=C2=A0 right=3D198.51.100.1=0A=C2=
=A0 rightauth=3Dpsk=0A=C2=A0 rightsubnet=3D10.191.2.0/24=0A=C2=A0 type=
=3Dtunnel=0A=0AThe shorewall configuration:=0A=0Ainterfaces:=0A?FORMAT 2=
=0A#ZONE=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 INTERFACE=C2=A0=C2=A0 OPTIO=
NS=0Aextpriv=C2=A0=C2=A0=C2=A0=C2=A0 eth0.1901=0Ainet=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0 eth0.1903=0Adnstrz1=C2=A0=C2=A0=C2=A0=C2=A0 eth=
1.1015=0A=0Azones:=0Afw=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0 firewall=0Aextpriv=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0 ip=0Ainet=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0 ip=0Adnstrz1=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0 ip=0Arz1trz2=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0 ipsec=0A=0Atunnels:=0A#TYPE=C2=A0=C2=A0=C2=A0=C2=A0 ZONE=
=C2=A0 GATEWAY(S)=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 GATEWAY=0A#=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
ZONE(S)=0Aipsecnat=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0 inet=C2=A0=C2=A0=C2=A0=C2=A0 198.51.100.1=0A=0Ahos=
ts:=0A#ZONE=C2=A0=C2=A0=C2=A0 HOSTS=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0 OPTIONS=0Arz1trz2=C2=A0 eth0.1903:10.192.2.0/24=
ipsec=0A=0Anetmap:=0A#TYPE NET1=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 INTERFACE=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0 NET2=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0 NET3=0ASNAT=C2=A0=C2=A0 10.138.53.229/32 eth=
0.1903=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 10.191.2.229/32 10.192.2.0/24=
=0ADNAT=C2=A0=C2=A0 10.191.2.229/32=C2=A0 eth0.1903=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0 10.138.53.229/32 10.192.2.0/24=0A=0Apolicy:=0A#SOURCE=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 DEST=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 POLICY=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 LOG LEVEL LIMIT:BURST=0Adnstrz1=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 rz1trz2=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ACCEPT=0Arz1trz2=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0 dnstrz1=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0 ACCEPT=0A# THE FOLLOWING POLICY MUST BE LAST=0Aall=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 all=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 DROP=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 $LOG=
=0A=0AI try to ping from the node 10.138.53.229 the node on the other si=
de:=0A10.192.2.229=0A=0AWith "tcpdump -i any -n host 10.192.2.229" on th=
e shorewall/IPsec node I=0Aonly see:=0A20:54:15.564946 eth1=C2=A0 In=C2=
=A0 IP 10.138.53.229 > 10.192.2.229: ICMP echo=0Arequest, id 34685, seq=
1, length 64=0A20:54:15.564947 eth1.1015 In=C2=A0 IP 10.138.53.229 > 10=
.192.2.229: ICMP echo=0Arequest, id 34685, seq 1, length 64=0A=0AAdding=
"iptables -t raw -I PREROUTING -d 10.192.2.229 -j TRACE" I can=0Asee th=
e following with "xtables-monitor --trace":=0APACKET: 2 53bdbe50 IN=3Det=
h1.1015 MACSRC=3D56:e9:84:3a:23:7e=0AMACDST=3D4a:b4:4a:4a:3b:39 MACPROTO=
=3D8100 SRC=3D10.138.53.229=0ADST=3D10.192.2.229 LEN=3D84 TOS=3D0x0 TTL=
=3D64 ID=3D2926DF=0A=C2=A0TRACE: 2 53bdbe50 raw:PREROUTING:rule:0x19:CON=
TINUE=C2=A0 -4 -t raw -A=0APREROUTING -d 10.192.2.229/32 -j TRACE=0A=C2=
=A0TRACE: 2 53bdbe50 raw:PREROUTING:return:=0A=C2=A0TRACE: 2 53bdbe50 ra=
w:PREROUTING:policy:ACCEPT=0A=C2=A0TRACE: 2 53bdbe50 mangle:PREROUTING:r=
eturn:=0A=C2=A0TRACE: 2 53bdbe50 mangle:PREROUTING:policy:ACCEPT=0A=C2=
=A0TRACE: 2 53bdbe50 nat:PREROUTING:return:=0A=C2=A0TRACE: 2 53bdbe50 na=
t:PREROUTING:policy:ACCEPT=0APACKET: 2 53bdbe50 IN=3Deth1.1015 OUT=3Deth=
0.1903 MACSRC=3D56:e9:84:3a:23:7e=0AMACDST=3D4a:b4:4a:4a:3b:39 MACPROTO=
=3D8100 SRC=3D10.138.53.229=0ADST=3D10.192.2.229 LEN=3D84 TOS=3D0x0 TTL=
=3D63 ID=3D2926DF=0A=C2=A0TRACE: 2 53bdbe50 mangle:FORWARD:rule:0x6:CONT=
INUE=C2=A0 -4 -t mangle -A=0AFORWARD -j MARK --set-xmark 0x0/0xff=0A=C2=
=A0TRACE: 2 53bdbe50 mangle:FORWARD:return:=0A=C2=A0TRACE: 2 53bdbe50 ma=
ngle:FORWARD:policy:ACCEPT=0APACKET: 2 53bdbe50 IN=3Deth1.1015 OUT=3Deth=
0.1903 MACSRC=3D56:e9:84:3a:23:7e=0AMACDST=3D4a:b4:4a:4a:3b:39 MACPROTO=
=3D8100 SRC=3D10.138.53.229=0ADST=3D10.192.2.229 LEN=3D84 TOS=3D0x0 TTL=
=3D63 ID=3D2926DF=0A=C2=A0TRACE: 2 53bdbe50 filter:FORWARD:rule:0x49:JUM=
P:dnstrz1_frwd=C2=A0 -4 -t=0Afilter -A FORWARD -i eth1.1015 -m policy --=
dir in --pol none -j dnstrz1_frwd=0A=C2=A0TRACE: 2 53bdbe50 filter:dnstr=
z1_frwd:rule:0xa8:JUMP:dynamic=C2=A0 -4 -t=0Afilter -A dnstrz1_frwd -m c=
onntrack --ctstate INVALID,NEW,UNTRACKED -j=0Adynamic=0A=C2=A0TRACE: 2 5=
3bdbe50 filter:dynamic:return:=0A=C2=A0TRACE: 2 53bdbe50 filter:dnstrz1_=
frwd:rule:0xab:JUMP:dnstrz1-inet -4=0A-t filter -A dnstrz1_frwd -o eth0.=
1903 -m policy --dir out --pol none -j=0Adnstrz1-inet=0A=C2=A0TRACE: 2 5=
3bdbe50 filter:dnstrz1-inet:rule:0x93:ACCEPT=C2=A0 -4 -t filter=0A-A dns=
trz1-inet -p icmp -m icmp --icmp-type 8 -m comment --comment Ping=0A-j A=
CCEPT=0A=C2=A0TRACE: 2 53bdbe50 mangle:POSTROUTING:return:=0A=C2=A0TRACE=
: 2 53bdbe50 mangle:POSTROUTING:policy:ACCEPT=0APACKET: 2 53bdbe50 IN=3D=
eth1.1015 OUT=3Deth0.1903 MACSRC=3D56:e9:84:3a:23:7e=0AMACDST=3D4a:b4:4a=
:4a:3b:39 MACPROTO=3D8100 SRC=3D10.138.53.229=0ADST=3D10.192.2.229 LEN=
=3D84 TOS=3D0x0 TTL=3D63 ID=3D2926DF=0A=C2=A0TRACE: 2 53bdbe50 nat:POSTR=
OUTING:rule:0x7:ACCEPT=C2=A0 -4 -t nat -A=0APOSTROUTING -s 10.138.53.229=
/32 -d 10.192.2.0/24 -o eth0.1903 -j NETMAP=0A--to 10.191.2.229/32=0A=0A=
with swanctl --list-sas I can see that no packets are going through the=
IPsec tunnel:=0A=C2=A0 rz1trz2: #1204, reqid 1, INSTALLED, TUNNEL,=0AES=
P:AES_CBC-256/HMAC_SHA2_256_128=0A=C2=A0=C2=A0=C2=A0 installed 10s ago,=
rekeying in 914s, expires in 1790s=0A=C2=A0=C2=A0=C2=A0 in=C2=A0 c1c3ef=
60,=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 0 bytes,=C2=A0=C2=A0=C2=A0=C2=A0 0 pac=
kets=0A=C2=A0=C2=A0=C2=A0 out c3cdf9d0,=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 0=
bytes,=C2=A0=C2=A0=C2=A0=C2=A0 0 packets=0A=C2=A0=C2=A0=C2=A0 local=C2=
=A0 10.191.2.0/24=0A=C2=A0=C2=A0=C2=A0 remote 10.192.2.0/24=0A=0AI am co=
nfused, why I do not see packages with source 10.191.2.229 going out eth=
0.1903 in the tcpdump output and why the trace ends with the nat:10.191.=
2.229:rule line.=0AHas someone an idea what I am doing wrong or how I ca=
n debug the issue further?=0A=0AThanks in advance for any help.=0A=0A=E2=
=80=8B=0A=0A
--=_4cd2eccb8c6fe0a9802f9b5e31f59b32
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; char=
set=3DUTF-8"><title></title><style type=3D"text/css">.felamimail-body-bl=
ockquote {margin: 5px 10px 0 3px;padding-left: 10px;border-left: 2px sol=
id #000088;} </style></head><body>I am trying to get an 1:1 NAT configur=
ed prior to sending the packages into an IPsec tunnel, but as far as I c=
an tell the NAT is never applied and the packages also never get into th=
e tunnel.<br><br>The IPsec tunnel configuration:<br><br>conn rz2trz1<br>=
auto=3Droute<br> closeaction=3Drestart<br> esp=3Daes2=
56-sha256-ecp384<br> ike=3Daes256-sha256-ecp384<br> ikelifet=
ime=3D60m<br> keyexchange=3Dikev2<br> left=3D192.0.2.1<br>&n=
bsp; leftauth=3Dpsk<br> leftsubnet=3D10.192.2.0/24<br> lifet=
ime=3D30m<br> right=3D198.51.100.1<br> rightauth=3Dpsk<br>&n=
bsp; rightsubnet=3D10.191.2.0/24<br> type=3Dtunnel<br><br>The shor=
ewall configuration:<br><br>interfaces:<br>?FORMAT 2<br>#ZONE  =
; INTERFACE OPTIONS<br>extpriv =
eth0.1901<br>inet =
eth0.1903<br>dnstrz1 eth1.1015<br><br>zon=
es:<br>fw firewall=
<br>extpriv ip<br>=
inet &n=
bsp; ip<br>dnstrz1 =
ip<br>rz1trz2 ips=
ec<br><br>tunnels:<br>#TYPE ZONE GATEWAY(S=
) GATEWAY<br># &nbs=
p; ZONE(S)<br>ipse=
cnat &n=
bsp; inet 198.51.100.1<br><br>hosts:<br>#ZONE&nb=
sp; HOSTS &nb=
sp; &nb=
sp; OPTIONS<br>rz1trz2 eth0.1903:10.192.2.0/24 ipsec<br><br>=
netmap:<br>#TYPE NET1 &nb=
sp; INTERFACE  =
; NET2 =
NET3<br>SNAT 10.138.53.229/32 eth0.1903 &n=
bsp; 10.191.2.229/32 10.192.2.0/24<br>DNAT =
10.191.2.229/32 eth0.1903 &nbs=
p; 10.138.53.229/32 10.192.2.0/24<br><br>policy:<br>#SOURCE &=
nbsp; DEST &n=
bsp; POLICY &=
nbsp; LOG LEVEL LIMIT:BURST<br>dnstrz1 &nbs=
p; rz1trz2 &n=
bsp; ACCEPT<br>rz1trz2 &n=
bsp; dnstrz1 ACCEP=
T<br># THE FOLLOWING POLICY MUST BE LAST<br>all &=
nbsp; all &nb=
sp; DROP &nbs=
p; $LOG<br><br>I try to=
ping from the node 10.138.53.229 the node on the other side:<br>10.192.=
2.229<br><br>With "tcpdump -i any -n host 10.192.2.229" on the shorewall=
/IPsec node I<br>only see:<br>20:54:15.564946 eth1 In IP 10.=
138.53.229 > 10.192.2.229: ICMP echo<br>request, id 34685, seq 1, len=
gth 64<br>20:54:15.564947 eth1.1015 In IP 10.138.53.229 > 10.19=
2.2.229: ICMP echo<br>request, id 34685, seq 1, length 64<br><br>Adding=
"iptables -t raw -I PREROUTING -d 10.192.2.229 -j TRACE" I can<br>see t=
he following with "xtables-monitor --trace":<br>PACKET: 2 53bdbe50 IN=3D=
eth1.1015 MACSRC=3D56:e9:84:3a:23:7e<br>MACDST=3D4a:b4:4a:4a:3b:39 MACPR=
OTO=3D8100 SRC=3D10.138.53.229<br>DST=3D10.192.2.229 LEN=3D84 TOS=3D0x0=
TTL=3D64 ID=3D2926DF<br> TRACE: 2 53bdbe50 raw:PREROUTING:rule:0x1=
9:CONTINUE -4 -t raw -A<br>PREROUTING -d 10.192.2.229/32 -j TRACE<=
br> TRACE: 2 53bdbe50 raw:PREROUTING:return:<br> TRACE: 2 53bd=
be50 raw:PREROUTING:policy:ACCEPT<br> TRACE: 2 53bdbe50 mangle:PRER=
OUTING:return:<br> TRACE: 2 53bdbe50 mangle:PREROUTING:policy:ACCEP=
T<br> TRACE: 2 53bdbe50 nat:PREROUTING:return:<br> TRACE: 2 53=
bdbe50 nat:PREROUTING:policy:ACCEPT<br>PACKET: 2 53bdbe50 IN=3Deth1.1015=
OUT=3Deth0.1903 MACSRC=3D56:e9:84:3a:23:7e<br>MACDST=3D4a:b4:4a:4a:3b:3=
9 MACPROTO=3D8100 SRC=3D10.138.53.229<br>DST=3D10.192.2.229 LEN=3D84 TOS=
=3D0x0 TTL=3D63 ID=3D2926DF<br> TRACE: 2 53bdbe50 mangle:FORWARD:ru=
le:0x6:CONTINUE -4 -t mangle -A<br>FORWARD -j MARK --set-xmark 0x0=
/0xff<br> TRACE: 2 53bdbe50 mangle:FORWARD:return:<br> TRACE:=
2 53bdbe50 mangle:FORWARD:policy:ACCEPT<br>PACKET: 2 53bdbe50 IN=3Deth1=
.1015 OUT=3Deth0.1903 MACSRC=3D56:e9:84:3a:23:7e<br>MACDST=3D4a:b4:4a:4a=
:3b:39 MACPROTO=3D8100 SRC=3D10.138.53.229<br>DST=3D10.192.2.229 LEN=3D8=
4 TOS=3D0x0 TTL=3D63 ID=3D2926DF<br> TRACE: 2 53bdbe50 filter:FORWA=
RD:rule:0x49:JUMP:dnstrz1_frwd -4 -t<br>filter -A FORWARD -i eth1.=
1015 -m policy --dir in --pol none -j dnstrz1_frwd<br> TRACE: 2 53b=
dbe50 filter:dnstrz1_frwd:rule:0xa8:JUMP:dynamic -4 -t<br>filter -=
A dnstrz1_frwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j<br>dynami=
c<br> TRACE: 2 53bdbe50 filter:dynamic:return:<br> TRACE: 2 53=
bdbe50 filter:dnstrz1_frwd:rule:0xab:JUMP:dnstrz1-inet -4<br>-t filter -=
A dnstrz1_frwd -o eth0.1903 -m policy --dir out --pol none -j<br>dnstrz1=
-inet<br> TRACE: 2 53bdbe50 filter:dnstrz1-inet:rule:0x93:ACCEPT&nb=
sp; -4 -t filter<br>-A dnstrz1-inet -p icmp -m icmp --icmp-type 8 -m com=
ment --comment Ping<br>-j ACCEPT<br> TRACE: 2 53bdbe50 mangle:POSTR=
OUTING:return:<br> TRACE: 2 53bdbe50 mangle:POSTROUTING:policy:ACCE=
PT<br>PACKET: 2 53bdbe50 IN=3Deth1.1015 OUT=3Deth0.1903 MACSRC=3D56:e9:8=
4:3a:23:7e<br>MACDST=3D4a:b4:4a:4a:3b:39 MACPROTO=3D8100 SRC=3D10.138.53=
.229<br>DST=3D10.192.2.229 LEN=3D84 TOS=3D0x0 TTL=3D63 ID=3D2926DF<br>&n=
bsp;TRACE: 2 53bdbe50 nat:POSTROUTING:rule:0x7:ACCEPT -4 -t nat -A=
<br>POSTROUTING -s 10.138.53.229/32 -d 10.192.2.0/24 -o eth0.1903 -j NET=
MAP<br>--to 10.191.2.229/32<br><br>with swanctl --list-sas I can see tha=
t no packets are going through the IPsec tunnel:<br> rz1trz2: #120=
4, reqid 1, INSTALLED, TUNNEL,<br>ESP:AES_CBC-256/HMAC_SHA2_256_128<br>&=
nbsp; installed 10s ago, rekeying in 914s, expires in 1790s<=
br> in c1c3ef60, 0=
bytes, 0 packets<br> out c3cd=
f9d0, 0 bytes, 0 p=
ackets<br> local 10.191.2.0/24<br> &n=
bsp; remote 10.192.2.0/24<br><br>I am confused, why I do not see package=
s with source 10.191.2.229 going out eth0.1903 in the tcpdump output and=
why the trace ends with the nat:10.191.2.229:rule line.<br>Has someone=
an idea what I am doing wrong or how I can debug the issue further?<br>=
<br>Thanks in advance for any help.<br><br>=E2=80=8B<br><br></body></htm=
l>
--=_4cd2eccb8c6fe0a9802f9b5e31f59b32--
--===============0868526779440321712==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============0868526779440321712==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline