Re: Could somebody enlighten me ;o)
Bart De Schuymer <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Op za, 28-05-2005 te 00:48 +0200, schreef Morten Bøgeskov: > Hello... > > I'm trying to make a firewall/accesspoint, and I want to be able to take > my tcp connectionsw with me, when I go from cable to wireless. So I've > bridged the eth2 (lan) and ath0 (wifi). Then security kicks in. I then > want to make an ipsec tunnel to the firewall to secure my wireless. This > part works too.. However I cannot get packages routed from the bridge out > the primary interface to go through the nat POSTROUTING iptable Perhaps Patrick McHardy can shed some light on this, IIRC he has worked on ipsec+bridge before... cheers, Bart > > eth0=x.x.x.x/24 > br_lan:[ath0, eth2]=y.y.y.50/28 > > simplified rules ;o) > > + iptables -t mangle -A PREROUTING -p ah -j MARK --set-mark 1 > + iptables -t mangle -A PREROUTING -p esp -j MARK --set-mark 1 > > + iptables -A FORWARD -i br_lan -m mark --mark 1 -j ACCEPT > + iptables -A FORWARD -i br_lan -m physdev --physdev-in eth2 -j ACCEPT > + iptables -A FORWARD -i br_lan -m physdev --physdev-in ath0 -j DROP > > + iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE > > + ebtables -P FORWARD DROP > + ebtables -A FORWARD -p ARP -j ACCEPT > > + ebtables -t nat -A PREROUTING --logical-in br_lan -p arp -j ACCEPT > + ebtables -t nat -A PREROUTING --logical-in br_lan -p ipv4 -j redirect --redirect-target ACCEPT > > On the firewall (y.y.y.50) > I have a racoon listening to interface x.x.x.x > And ipsec (setkey) saying anything to or from x.x.x.x should not be encrypted > > On the laptop (y.y.y.53): > Everything should be encrypted > Except anything to or from x.x.x.x > > This works like a charm on the bridge: > # ping y.y.y.52 > tcpdump: > 23:44:52.652905 IP y.y.y.53 > x.x.x.x: ESP(spi=0x0acdda0e,seq=0x104) > 23:44:52.656517 IP x.x.x.x > y.y.y.y.53: ESP(spi=0x0ad3a55e,seq=0x110) > 23:44:52.656517 IP y.y.y.52 > y.y.y.53: icmp 64: echo reply seq 28929 > > However when going out eth0 does not get natted on the way out of the > firewall. > e.g: > lap# ping slashdot.org > fw# iptables -t mangle -I POSTROUTING -j LOG --log-prefix 'mangle:POSTROUTING ' > fw# iptables -t nat -I POSTROUTING -j LOG --log-prefix 'nat:POSTROUTING ' > fw# tcpdump -i eth0 -n -p > 23:47:16.022751 IP x.x.x.53 > 66.35.250.150: icmp 64: echo request seq 0 > fw# dmesg > mangle:POSTROUTING IN= OUT=eth0 PHYSIN=ath0 SRC=172.19.1.53 DST=66.35.250.150 LEN=84 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=51259 SEQ=0 > > I was expecting both mangle & nat chains in the syslog as well as x.x.x.x > instead of y.y.y.53 in the tcpdump. The funny part is that everyting woeks > as expected from y.y.y.52 (which does not go through the ipsec). > > Does anybody have any idea why I don't hit the nat POSTROUTING table when > using ipsec over the bridge? > > When I make a setup with ath0 an individual interface (not enslaved by a > bridge) it works like a charm¹ (except I get an ip number that doesn't > suit me ;o) > > > ¹) ath0 192.168.1.1/24 > laptop 192.168.2.1/24 gateway 192.168.1.1 > ipsec setup like before > ping slashdot.org works > ping y.y.y.52 works > > Yours > -- > Morten Bøgeskov (email: morten-jGWyxZGbRXZknbxzx/[email protected]) > > Maybe you just don't care about your sensitive data as much as I do: > all my important textual data has been encrypted into a binary format > according to the American Standard Code for Information Interchange. > > > ------------------------------------------------------- > This SF.Net email is sponsored by Yahoo. > Introducing Yahoo! Search Developer Network - Create apps using Yahoo! > Search APIs Find out how you can build Yahoo! directly into your own > Applications - visit http://developer.yahoo.net/?fr=offad-ysdn-ostg-q22005 > _______________________________________________ > Ebtables-user mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/ebtables-user > ------------------------------------------------------- This SF.Net email is sponsored by Yahoo. Introducing Yahoo! Search Developer Network - Create apps using Yahoo! Search APIs Find out how you can build Yahoo! directly into your own Applications - visit http://developer.yahoo.net/?fr=offad-ysdn-ostg-q22005