sunscreen vpn

From: Stefan sellmer (S_At_work_at_gmx.net)
Date: 10/08/03

  • Next message: Kenneth Denski: "Account Lockout in Solaris 8"
    Date: Wed, 8 Oct 2003 10:58:43 +0200 (MEST)
    To: focus-sun@securityfocus.com
    
    

    hello.

    i have 3 maschines.
    1) ultra1
    (hme0 139.23.207.30/hme0:1 139.25.207.27)

    2)ultra10
    (hme0 139.23.207.28/hme0:1 139.24.207.11)

    3)pc(linux)
    (eth0 139.24.207.27)

    Now i have to build a vpn tunnel/ or another ipsec encryption form, between
    the two ultras.

    pc< ----(Plain)---->ultra10<---(encrypted)---->Ultra1

    But the connection between the pc and ultra10 should be pain-text.

    Now i want ping from pc to the second interface of ultra1(hme0:1
    139.25.207.27), and the ping packet should be routed through the encrypted vpn-tunnel,
    and back.

    i use the sunscreen firewall on both ultras.
    i used this tutorial
    http://docs.sun.com/db/doc/806-6348/6jfa1eop1?a=view

    but it don't work, every time when i try to ping from pc to ultra1(hme0:1
    139.25.207.27), it is sended as an normal ping.

    if i have in the filtering rules only the vpn rule nothing happends, but if
    i add a rule which allow all traffic the ping packet will be routed to
    ultra1(hme0:1 139.25.207.27)(plain text of course). is this normal ??

    where are the logs ??
    can i see in any log what is going wrong ??
    have anybody helpfull tips?

    please help because i have set up my network similar to the
    http://docs.sun.com/db/doc/806-6348/6jfa1eop1?a=view
    tutorial, the only difference is that i ping not a host but a secondary
    interface .

    thanks in advance

    stefan

    -- 
    NEU FÜR ALLE - GMX MediaCenter - für Fotos, Musik, Dateien...
    Fotoalbum, File Sharing, MMS, Multimedia-Gruß, GMX FotoService
    Jetzt kostenlos anmelden unter http://www.gmx.net
    +++ GMX - die erste Adresse für Mail, Message, More! +++
    

  • Next message: Kenneth Denski: "Account Lockout in Solaris 8"

    Relevant Pages

    • RE: VPN via extended firewall toSBS2003
      ... VPN via extended firewall toSBS2003 ... >I can ping the IP number of the server, ... >> Please make sure that the corporate LAN and the remote XP computer's local network are not sharing ... >> Bill Peng ...
      (microsoft.public.windows.server.sbs)
    • Cant Ping My Own IP Address
      ... I was running a VPN ... Another computer attached to the same router has ... trouble getting out to the Internet and this second machine can ping ... The WINS settings are to enable LMHOSTS lookup and the NetBIOS is set ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Unable to ping a workstation
      ... Networking, Internet, Routing, VPN Troubleshooting on ... How to Setup Windows, Network, VPN & Remote Access on ... started the workstation does not ping. ...
      (microsoft.public.windowsxp.network_web)
    • Re: Cant Ping My Own IP Address
      ... I was running a VPN ... Ever since then my Internet connectivity is VERY sporadic. ... > trouble getting out to the Internet and this second machine can ping ... > I also tried connecting the VPN again and disconnecting it. ...
      (microsoft.public.windowsxp.general)
    • Re: VPN Routing Problem
      ... Adding the correct route via the route ... I've run the ipconfig command on client and server and some ... On the VPN Server subsequent to a successful VPN connection from the vpn ... Results of trying to Ping the KWF6 host by name from the VPN client ...
      (alt.os.windows-xp)