Re: GRE and PF problem

From: Giovanni P. Tirloni (gpt_at_tirloni.org)
Date: 07/14/05

  • Next message: Alex Povolotsky: "Re: GRE and PF problem"
    Date: Thu, 14 Jul 2005 09:51:48 -0300
    To: Alex Povolotsky <tarkhil@webmail.sub.ru>
    
    

    Alex Povolotsky wrote:
    > compunction wrote:
    >
    >> GRE needs to pass bidirectional. You will need a binat to make it
    >> work. I have not found a firewall that will allow GRE to work with a
    >> many to one nat.
    >>
    >>
    >
    > The most painful thing is that pf's nat works for GRE - SOMETIMES :-(
    >
    > The only thing firewall needs to implement for natting GRE is creation
    > of two rules (forward and back) for GRE packet, just like it does for ICMP.
    >
    > I'm not a firewall writer, but as far as I understand general procedural
    > programming, it cannot be THAT complicated.

      When a packet comes from 1.2.3.4 to your external interface you can't
    determine if it's destined to 192.168.0.1 or 192.168.0.2 if both
    initiated a GRE tunnel to 1.2.3.4. That's because GRE doesn't have ports
    like UDP or TCP to make (de)multiplexing possible, AFAIK.

      http://www.networksorcery.com/enp/protocol/gre.htm

    -- 
    Giovanni P. Tirloni / gpt@tirloni.org / PGP: 0xD0315C26
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Alex Povolotsky: "Re: GRE and PF problem"

    Relevant Pages

    • Re: Error 720 connecting to server via VPN
      ... Actually I've just tired that firewall rules and it didn't work. ... VPN client is not configured to allow Generic Routing Encapsulation (GRE) ... Should I setup a firewall rules to allow port 47? ... Port 1723 is allowed in my router for any WAN users to the server. ...
      (microsoft.public.windows.server.sbs)
    • Re: Problems Logon on Ras Server
      ... my Router Zyxel 652, is also a firewall. ... In the the protocols list that i enable to pass trought firewall check, ... >> On my firewall,I have open ports for PPTP and GRE. ... > protocol. ...
      (microsoft.public.win2000.ras_routing)
    • Re: VPN Problem Ereignis 20209
      ... Pruefe doch mal deine Firewall, ob die Generic Routing Encapsulation (GRE) ... packets blockt. ... A connection between the VPN server and the VPN client has been ...
      (microsoft.public.de.german.windows.server.networking)
    • Re: Vista VPN
      ... Check the advanced firewall settings on the Vista box. ... setting that's messing up L2TP or not, but that GRE one will kill outbound ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN PPTP
      ... When you say "fails" do you get an error or does it just hang? ... then I would double check your firewall and GRE. ... Are you using the PIX as your firewall? ...
      (microsoft.public.windows.server.sbs)