Linux v Dedicated NAT routers - secure remote differences

From:
Date: 09/27/02


Date: Fri, 27 Sep 2002 21:06:13 GMT

My collegues, using NAT routers (such as Netgear RP114) can get a secure
remote tunnel from a Windoze machine behind it to talk through a Checkpoint
FW-1 firewall. I can't with a linux NAT box. WHY?

More details ...

My company allows remote laptop computers connected via the internet
to access its internal systems using secure remote installed on the
laptop. We all have little Secure ID cards that calculates a time
windowed password for these as an added security. The set up defines
UDP encapsulation with IKE. The company uses the Checkpoint
Firewall-1

I can connect my Win98 laptop via a dial up connection to the
internet, and this setup works.

At home I have a small internal network controlled by a linux box
acting as a firewall, NAT device and gateway onto a cable modem based
in IPTABLES. Sitting behind this box, attempts to connect my win98
laptop using secure remote fail.

A number of other people have purchased dedicated
Router/Hubs (Netgear RP114 is one such device) for their cable
providers and are then connecting their laptops to these. All of
these people report that their version of secure remote works just
fine.

Win98 --- Linux --- Internet --- FW-1 --- Internal company

Above configuration fails

Win98 --- Netgear RP114 --- Internet --- FW-1 --- Internal company

Above configuration works

I spent some time running ethereal on my linux box and a contact inside the
internal IT department on the phone looking at the other end trying to see
why it didn't work. I communicate with the firewall and negotiate the key
exchange correctly. My PC then tries to use the encrypted channel to talk
to internal services (I was trying NNTP connection to a news service) and
I see the packet go out, but no reply comes back. My IT department
collegue reports that the IP address allocated by DHCP by my linux
router (10.0.10.30) is seen as the return address of the decrypted
packets inside the company - so when I access a service the reply does
not know how to get routed back to me.

The problem is, that now that other solutions are seen to work no one is
prepared to spend more time helping me get my linux solution working. I am
pretty sure that these devices are acting as also acting as NAT devices
(one collegue has told me he had been allocated 10.0.0.152 as his IP
address).

I have tried reading the Linux VPN HowTo, but these seem to assume
that the tunnel starts at the linux box rather than on a NAT'ted
machine behind.

Could someone explain in simple terms how the setup I am describing
should work and what could be the differences between what I could be
doing with standard linux (2.4.18) and whatever might be in these
routers (I assume these are quite likely to be linux variants).

Thanks

-- 
Alan Chandler



Relevant Pages

  • Re: Web-based remoting...
    ... Linux capabilities as far as being able to allow a remote user to (via ... seems that it might be relavant is that my home PC is running SuSE ... It is intended to replace rlogin and rsh and provides secure ...
    (alt.os.linux.suse)
  • Re: Ten least secure programs
    ... Subject: Ten least secure programs ... only someone that's hard up to bash Linux users would assume this. ... > corrected virtually all current and yet to be discovered security issues ...
    (Security-Basics)
  • RE: Ten least secure programs
    ... contrary to the statistics. ... corrected virtually all current and yet to be discovered security issues ... with Linux. ... Subject: Ten least secure programs ...
    (Security-Basics)
  • RE: Religion... was RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... there is no A/V software for Linux that protects ... Of course, many of them do run A/V software, but it's to protect Windows ... In today's environment, software *must* be secure first, with usability added ... Microsoft systems take the opposite approach, ...
    (Full-Disclosure)
  • Re: copssh, WinScp, Tunnelier, Etc.
    ... I am seeking a secure way to share files with other computers ... was directed to copssh and WinScp or Tunnelier. ... You do realize you are now securing the computers for Remote ... Does the file transfer go both ways and with both ways having ...
    (microsoft.public.windowsxp.work_remotely)