how to open protocol 47 on a netscreen firewall?

From: Alex Hunsley (lard_at_tardis.ed.ac.molar.uk)
Date: 12/15/04

  • Next message: Alex Hunsley: "Re: how to open protocol 47 on a netscreen firewall?"
    Date: Wed, 15 Dec 2004 10:59:25 GMT
    
    

    I'm setting up a netscreen 25 firewall to use NAT.
    All is working fine except that people can't VPN in (using PPTP preferably).
    (I want people to be able to VPN in to a VPN server on the inside and
    not use the built-in VPN abilities of the netscreen).

    I'm finding messages everywhere saying that to allow me to do this, I
    have to allow in PPTP protocol, which I've done, but I also have to
    "allow protocol 47" - what exactly is meant by this? In the services
    rule, I can create a service with a specific IP type - is this what they
    mean? I've tried doing this - creating a service that allows all ports
    to all ports with IP proto 47 allowed, but this isn't working.
    Can anyone shine any light on what exactly "open protocol 47" means in
    terms of a netscreen firewall?

    thanks
    alex


  • Next message: Alex Hunsley: "Re: how to open protocol 47 on a netscreen firewall?"

    Relevant Pages

    • Re: [SLE] Roadwarriors, VPN or pptp?
      ... > I'm using PPTP for some of our remote users, but that's because I have Win ... > poptop on a SnapGear firewall, though I'm planning to start moving to ipsec ... pptp is not as secure of a vpn ... Also recommended for consideration is Astaro Secure Linux. ...
      (SuSE)
    • PPTP VPN pass-thru
      ... it doesn't support PPTP VPN ... didn't encrypt or integrity-check the TCP/UDP headers themselves, so NAT ... so would break the protocol. ...
      (uk.comp.sys.mac)
    • RE: Sandboxing
      ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
      (Focus-IDS)
    • Re: [SLE] Roadwarriors, VPN or pptp?
      ... I'm using PPTP for some of our remote users, but that's because I have Win ... pptp is not as secure of a vpn ... Not that you necessarily want to buy a new firewall device, ... allows direct iptables rule setting (or the use of a nifty ...
      (SuSE)
    • Input/Opinions Appreciated (Topic for Discussion)
      ... and then PAT'ing PPTP ports to a Win2k server. ... a VPN to the firewall is more secure, ... oriented company, and this is a very possible reality ("you know how ...
      (comp.security.misc)

  • Quantcast