firewalling with tunnels, and/or ipv6

From: Charlie Schluting (charlie_at_schluting.com)
Date: 12/21/04

  • Next message: gnn_at_FreeBSD.org: "Re: FreeBSD Router : ARP who-has requests"
    Date: Mon, 20 Dec 2004 18:05:16 -0800
    To: freebsd-net@freebsd.org
    
    

    Ok, I've got a v6 tunnel, and to make it work I had to "allow ipv6 from
    <endpoint>" in ipfw. From what I understand, I have to make a completely
    different set of rules for ipv6, and load them using the -6 flag.

    Correct so far?

    Ok, so I want to set up an ipip v4 tunnel to another box (that runs
    ipf), and then squirt ipv6 through the tunnel. Sounds easy, but I can't
    even seem to get the ipip tunnel working.
    The question:
    How do you configure ipf/ipfw (in a general sense) to allow ipip
    tunnels? More importantly, if I "allow ipip from <IP>" does that mean I
    just poked a big ass hole in the firewall... i.e. anything coming
    through the ipip tunnel will pass? Or, does that make an IP layer be
    shed, then the packet is run through all the rules again? Inefficient,
    but I'd think this would be the desired behaivor.
    At any rate, simply allowing ipip from <host> doesn't allow the v4
    tunnel to work. What else is needed? (of course static routes, etc.)

    I think I'll stop here for now; once that's clear I should be able to
    set it up.

    Thanks,

    _Charlie
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: gnn_at_FreeBSD.org: "Re: FreeBSD Router : ARP who-has requests"

    Relevant Pages

    • Re: IP-IP encapsulation..
      ... an IPIP tunnel and the behaviour you just described? ... IP-encapsulated IP packets.. ... tauno voipio iki fi ...
      (comp.os.linux.development.apps)
    • Re: [fw-wiz] IPv6 and IPSec
      ... >> Now, as a system administrator, how are you going to track down a virus ... network to network). ... Nice thing is that, with IPv6, you can have ... up an IPv6 tunnel back out that slid right past all the IDS they had. ...
      (Firewall-Wizards)
    • Re: ipv6 confusion
      ... The machine I want to do the tunneling on is behind a NAT'ed firewall ... so it can receive all of your incoming IPv6 traffic. ... Pick the tunnel with the least delay! ... LAN get other IPv6 addresses, all with the same initial 48 bits (I.E. ...
      (freebsd-questions)
    • Configuring ipv6 on cisco 877
      ... I have a cisco 877 that's been working fine (after an RMA on the first ... ipv6 addresses on the other end of the tunnel. ... A debug log shows the packets going ... Of course it's possible the tunnel broker is dead (it worked 2 years ...
      (comp.dcom.sys.cisco)
    • Re: LAN addresses in IPv6
      ... Starting AICCU (Automatic IPv6 Connectivity Configuration Utility) services: ... Tunnel Information for T20165: ... those to Centos boxes. ...
      (Fedora)