FW: ipfw, natd and routing question

From: Robin Huiser (robin@bequbed.com)
Date: 06/11/01


From: "Robin Huiser" <robin@bequbed.com>
To: <freebsd-security@FreeBSD.ORG>
Date: Mon, 11 Jun 2001 16:47:29 +0200

Hi all,

I hope someone can help me with this problem I'm trying to solve. I think
the answer is trivial, but so far I 'm stuck.

Our FreeBSD 4.2-STABLE firewall has three network cards as shown below:

                                -- DMZ
                               /
               EXT--FIREWALL---
                               \
                                -- LAN

-The EXT interface: connected to the Internet, IP subnet x.x.242.32/240
-The DMZ interface: connected to our DMZ subnet, IP subnet x.x.242.48/240
-The LAN interface: connected to our LAN subnet, IP subnet 192.168.1.0/24

I use NAT to 'route' traffic from the LAN to the Internet
I use ipfw rules to ROUTE traffic from the Internet to the DMZ subnet

So far, so good.

But... how do I prevent the NAT to 'translate' the IP addresses when a
session is set up from the DMZ segment to a host somewhere on the Internet?
I want all traffic to be routed from the DMZ subnet to the Internet...

I've tried to alter the natd rule, without any success.
The rules I tried didn't work or had bad side effects, so I moved back to
the standard natd rule, but everything gets NAT-ed now...

Some examples I tried:

#
# The rule below works, but the it causes TCP/IP timeouts and a *very* slow
# connection between the DMZ and EXT subnets...
#
${fwcmd} add divert natd all from not x.x.242.48:255.255.255.240 to any
via ${natd_interface}

#
# The rule below doesn't work at all (?) Don't know why...
#
${fwcmd} add divert natd all from 192.168.1.0:255.255.255.0 to any via
${natd_interface}

Please advise...

Cheers -- Robin

__________________________________________________________________

Robin Huiser robin@bequbed.com
BeQubed N.V. http://www.bequbed.com

Veenwal 130 tel: +31 (30) 6023 626 (OFFICE)
3432 ZE +31 (6) 2061 9842 (MOBILE)
Nieuwegein fax: +31 (30) 6586 090
The Netherlands
__________________________________________________________________

======================Confidential Disclaimer=====================

The information contained in this communication is confidential and is
intended solely for the use of the individual or entity to whom it is
addressed. You should not copy, disclose or distribute this communication
without the authority of BeQubed N.V. BeQubed is neither liable for the
proper and complete transmission of the information contained in this
communication nor for any delay in its receipt.
BeQubed does not guarantee that the integrity of this communication has been
maintained nor that the communication is free of viruses, interceptions or
interference.

If you are not the intended recipient of this communication please return
the communication to the sender and delete and destroy all copies.

In carrying out its engagements, BeQubed applies general terms and
conditions, which contain a clause that limits its liability. A copy of
these terms and conditions is available on request free of charge.
==================================================================

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Routing and RRAS Problem - Pleasehelp
    ... Traffic from your "internal" subnet can get ... out to the Internet by default routing, but the return traffic will fail. ... You need to add an extra route to the Linksys router so that it knows how to ...
    (microsoft.public.windows.server.networking)
  • Re: Problem with IPSEC
    ... rules like this work on an internal subnet. ... addresses or even a subnet on the internet it doesn't work. ... Turn off IPSEC. ... yes ipsec filters are weighted such that a specific rule ...
    (microsoft.public.windows.server.security)
  • Re: Routing and RRAS Problem - Pleasehelp
    ... use RRAS but if will fail I will run RRAS server as NAT Router, ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... Traffic from your "internal" subnet can get ... You need to add an extra route to the Linksys router so that it knows how to ...
    (microsoft.public.windows.server.networking)
  • Re: Routing and RRAS Problem - Pleasehelp
    ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... but the problem is the PC's on the subnet 1 cannot access the Internet. ... router that is running a DHCP, The IP of the router is ... enable RRAS, and is running fine, Interface called INTERNET is connected to ...
    (microsoft.public.windows.server.networking)
  • Re: Single 2003 Server with DHCP, DNS and ISA 2006
    ... As soon as I created my own DHCP ... I can ping the server by IP address and name from the workstation. ... Not too surprising with the above subnet problems. ... To the Internet. ...
    (microsoft.public.windows.server.general)