Re: SecuRemote Client and Netfilter NAT

From: Frederik (frederik@padjen.de)
Date: 05/30/02


Date: Thu, 30 May 2002 00:00:02 +0200
From: Frederik <frederik@padjen.de>
To: brien mac <aph3x@linuxmail.org>

Hello there,

I am not sure about this as I am unfamiliar with the aforementioned client,
but have you tried compiling and insmodding all netfilter modules?
Maybe this is a bit like NAT'ed ftp,where there are special modules needed
for the server.
You already mentioned you used force_udp_encapsulation,if you have not yet
tried other
UDP modules it might be worth the try.

greetings
Frederik

On 2002.05.29 02:56:37 +0200 brien mac wrote:
> hello all... :)
>
> i currently have a small home network (five nodes) in which a slackware 8
> box is NAT'ing the internal network using iptables 1.2.6a.
>
> my roomate's employer has provided him with a DSL connection which
> permits him to work from home. however, in order to access the corporate
> network securely, he must authenticate himself using SecuRemote 4.1
> (SP-1). in order for me to also be able to use this DSL, for free ;), he
> needs to be able to access the network.
>
> a packet analysis revealed that UDP 259 was needed for authentication. i
> configured Netfilter to accept FORWARD outbound UDP 259 traffic in state
> NEW and ESTABLISHED and to accept FORWARD inbound UDP 259 traffic in
> state ESTABLISHED. i read the article on
> http://lists.samba.org/pipermail/netfilter/2002-February/019769.html and
> added "force_udp_encapsulation (true)" to the userc.c file. before doing
> this, authentication between the client and gateway was unsuccessful; the
> authentication process, according to the SecuRemote client, is now
> successful.
>
> the problem im having, occurs when my roomate uses an application, called
> Accessory Manager, to access the corporate network. another packet
> analysis revealed that my roomate's computer was attempting to transmit
> data to the VPN gateway using protocol 94, which i found through further
> research, to be ip in ip (IPIP).
>
> outbound requests were made by my roomate's computer, but no responses
> were received from the VPN gateway. in addition, my firewall's logs did
> not report any denied packets for inbound or outbound data transmission.
> this leads me to believe that the packets were not even being forwarded,
> perhaps because of IPIP.
>
> i recompiled my linux kernel with IP Encapsulation support and tried
> again... this time authentication was unsuccessful. so, im wondering,
> what am i doing correctly and what am i doing incorrectly?
>
> any related links/advice/suggestions are welcomed and appreciated :)
>
> thanks for your time,
>
> Brien - a.k.a VPN newbie
>
>
>
>
>
>
>
> --
> Get your free email from www.linuxmail.org
>
>
> Powered by Outblaze
>
>



Relevant Pages

  • RE: Wireless Security Notes and Findings (from this list and other places)
    ... There are two general areas of wireless security: Authentication and ... authentication standard that works with wireless networks. ... client computer runs a client program to connect to the network with a ...
    (Security-Basics)
  • RE: 802.1x, Computers, Wired Security
    ... client to use EAP-TLS. ... Authentication-Provider = Windows ... Wired 802.1X Authentication failed. ... Network Adapter: Broadcom NetXtreme Gigabit Ethernet - Packet Scheduler ...
    (microsoft.public.windows.server.active_directory)
  • Re: IIS 6.0 and 401.2 and 401.1 Errors
    ... > authentication -- client and server first negotiate authentication that ... > So, if you see repeated 401.2 for the same resource from the same client, ... > authenticated connection and instead RENEGOTIATING a new connection. ... > You can easily verify this by installing "Network Monitor" from Windows ...
    (microsoft.public.inetserver.iis)
  • Re: Socket weirdness
    ... client) before you will notice a shutdown receive at server. ... Then eventually a packet comes from the peer, and that will contain data, so the server responds RST: ... way back across the network. ...
    (microsoft.public.dotnet.framework)
  • Re: 2003 AD XP Client domain name change
    ... One of the main problems with this scenario is that once a 2K/XP client ... Currently have an AD 2003 test network setup in interim ... authentication purposes. ... connection with the server ...
    (microsoft.public.win2000.active_directory)