Re: GRE and PF problem

From: compunction (compunction_at_gmail.com)
Date: 07/14/05

  • Next message: Alex Povolotsky: "Re: GRE and PF problem"
    Date: Thu, 14 Jul 2005 01:31:36 -0400
    To: Alex Povolotsky <tarkhil@webmail.sub.ru>
    
    

    GRE needs to pass bidirectional. You will need a binat to make it
    work. I have not found a firewall that will allow GRE to work with a
    many to one nat.

    -Mark

    On 7/13/05, Alex Povolotsky <tarkhil@webmail.sub.ru> wrote:
    > Hello!
    >
    > I'm using FreeBSD (5.3-RELEASE-p5) as internet access server, and I have
    > to NAT GRE packets. I'm using pf.
    >
    > The problem is that SOMETIMES PF fails to create proper rule using nat,
    > while binat works fine.
    >
    > Not only I do not want to expose Windows boxes (even if those addresses
    > are firewalled), but it's also a terrible waste of real IPs.
    >
    > Can anyone point me if I have incorrect PF config, or PF just work
    > poorly with gre?
    >
    > Alex.
    >
    >
    > _______________________________________________
    > freebsd-net@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-net
    > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    >
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Alex Povolotsky: "Re: GRE and PF problem"

    Relevant Pages

    • Re: Error 720 connecting to server via VPN
      ... Actually I've just tired that firewall rules and it didn't work. ... VPN client is not configured to allow Generic Routing Encapsulation (GRE) ... Should I setup a firewall rules to allow port 47? ... Port 1723 is allowed in my router for any WAN users to the server. ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN-Server macht von extern Probleme
      ... > ist von extern her erreichbar (NAT auf der Firewall). ... Welche Ports/Protokolle hast Du aufgemacht bzw. leitest Du per NAT an den ... Für PPTP benötigst Du 1723/tcp eingehend sowie GRE (Protokoll 47). ...
      (microsoft.public.de.german.isaserver)
    • Re: Problems Logon on Ras Server
      ... my Router Zyxel 652, is also a firewall. ... In the the protocols list that i enable to pass trought firewall check, ... >> On my firewall,I have open ports for PPTP and GRE. ... > protocol. ...
      (microsoft.public.win2000.ras_routing)
    • Re: VPN Problem Ereignis 20209
      ... Pruefe doch mal deine Firewall, ob die Generic Routing Encapsulation (GRE) ... packets blockt. ... A connection between the VPN server and the VPN client has been ...
      (microsoft.public.de.german.windows.server.networking)
    • Re: Vista VPN
      ... Check the advanced firewall settings on the Vista box. ... setting that's messing up L2TP or not, but that GRE one will kill outbound ...
      (microsoft.public.windows.server.sbs)