SunScreen troubleshooting tips?

From: amaret@tradewinds-solutions.com
Date: 01/16/02


To: focus-sun@securityfocus.com
From: amaret@tradewinds-solutions.com
Date: Wed, 16 Jan 2002 19:54:22 +0100

hello

We have setup the following network structure:

host.A <<==>> (hme0) fw.A (hme1) <<==>> (hme1) fw.B (hme0) <<==>>
host.B

fw.A and fw.B both run SunScreen 3.1, traffic between fw.A and fw.B is sent
over an encrypted VPN.
All interfaces are in routing mode (not stealth)

Some troubleshooting is required... so:

I want to ping host.B from fw.A. I want the packet to originate from the
firewall's private interface
(hme0) and go through the VPN. How do I do that ?

I'd also like to snoop on the VPN's traffic only. If I'm right there is no
"virtual interface" tied to
the VPN so I can't use snoop's "-d" switch. How ?

Thanks in advance

  alex



Relevant Pages

  • Re: Configuring Cisco VPN Client / Windows XP
    ... Packets will use an interface based on the routing table. ... Generally speaking when the VPN is connected it will add a route to the ... flush the DNS Cache resolver to clear out the old DNS ... > cannot access the *same* pages on the computer with the VPN client ...
    (comp.dcom.vpn)
  • Re: VPN Problems
    ... in the Cisco VPN Client Log I am getting: ... interface: outside ... port-object eq echo ... crypto dynamic-map RemoteVPNDynmap 10 set transform-set RemoteVPNSet ...
    (comp.dcom.sys.cisco)
  • Re: ASA 5510 Route Question
    ... My thought process was that I would dedicate one T1 to strictly carry VPN traffic, while the other handles all other internet traffic. ... I hope to eliminate congestion to my spoke VPN sites due to excessive internet traffic. ... interface has no nat, but a crypto map assigned to it. ... Should I, as part of configuring VPN connectivity for each site, assign a static route for 192.168.X.0/24 to point out the VPN interface on the 5500? ...
    (comp.dcom.sys.cisco)
  • Re: VPN IP Addressing Problem
    ... If I took the public IP I am using for PAT and applied it to the ... to the inside interface of the Router. ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the LAN ...
    (comp.dcom.sys.cisco)
  • ASA 5510 Route Question
    ... spoke VPN sites due to excessive internet traffic. ... interface has no nat, but a crypto map assigned to it. ... If I assign a static route for the INET interface, ...
    (comp.dcom.sys.cisco)