Re: SunScreen troubleshooting tips?

From: Scott Morris (hexjunky@yahoo.com)
Date: 01/16/02


From: "Scott Morris" <hexjunky@yahoo.com>
To: <focus-sun@securityfocus.com>
Date: Wed, 16 Jan 2002 21:42:00 +0800

As far as your first question:

> I want to ping host.B from fw.A. I want the packet to originate from the
> firewall's private interface
> (hme0) and go through the VPN. How do I do that ?

use the -i option for ping

          -i interface_address
                Specify the outgoing interface address to use for
                multicast packets for IPv4 and both multicast and
                unicast packets for IPv6. The default interface
                address for multicast packets is determined from
                the (unicast) routing tables. interface_address
                can be a literal IP address, for example,
                10.123.100.99, or an interface name, for example,
                le0, or an interface index, for example 2.

>
> I'd also like to snoop on the VPN's traffic only. If I'm right there is no
> "virtual interface" tied to
> the VPN so I can't use snoop's "-d" switch. How ?

Since it is VPN traffic, you could just look for the IKE ( or whatever )
packets...
Just pick the interface the traffic is leaving from.

-Scott Morris


_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



Relevant Pages

  • Re: ipv4 regression in 2.6.31 ?
    ... interface eth1 on host B and let host A ping 192.168.2.1 you get no reply. ... Each incoming packet is tested against the FIB and if the interface ... Current recommended practice in RFC3704 is to enable strict mode ...
    (Linux-Kernel)
  • Re: sent an invalid ICMP type 11, code 0 error to a broadcast: 0.0.0.0 on lo?
    ... > If you ping an IP address on your computer, ... > the lo route filtering altogether. ... ICMP packet, with source address on this same box. ... IF that packet comes from the interface where the default ...
    (Linux-Kernel)
  • Re: PIX: Ping VPN host from inside network
    ... to ping hosts in the vpn subnet pool or vice-versa. ... The same capture applied to the outside interface shows pings heading ... access-list inside_nat0_outbound extended permit ip any 192.168.24.0 ... access-group outside_access_in in interface outside ...
    (comp.security.firewalls)
  • Re: Linux routing mystery. No replies until machine sources traffic.
    ... The machine has an interface on each of these ... You cannot have more than one default route. ... A machine can ping ... 1.1.1.0/24 dev eth0 proto kernel scope link src 1.1.1.5 ...
    (comp.os.linux.networking)
  • Re: Forcing a packet through an interface (OT?)
    ... add a static route ... > How could I force a packet to go out through an interface, ... How could I force a packet (ping maybe?) ...
    (freebsd-hackers)