Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

IPChains Masquerade Q

Thread Tools
 
Search this Thread
 
Old 11 November 2002 | 09:49 AM
  #1  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

I'm struggling to get a MS PPTP VPN working through a Linux IPChains firewall (IPCop). The intial connection (TCP 1723) is being masqueraded but the source port is being translated to a high port (>61000). Connections work fine direct or through an IOS firewall (which keeps the original Source Port).

For some reason it appears the firewall at the other end of the VPN doesnt seem to like he high source port. I have no access to check/change this so need to persuade the IPChains firewall to leave the source port alone (unless there is a conflict).

The IPChains box is only sharing an ISDN connection for a small home network (my Parents) so conflicts should be rare.

Anyone know how to get IPChains to use the original Source Port ?

Thanks
Deano
Old 12 November 2002 | 10:17 AM
  #2  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

*cough* anybody ?
Old 12 November 2002 | 03:49 PM
  #3  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Do you have an IP range external to the Linux firewall that you could NAT you PPTP connection ?

This is typically how HIDE (or Dynamic) NATing works to allow it to now which internal host orginated the packets (ie changing the source port). Firewalls tend to be critical of the destination port rather than the source. Do you know what the device is that you are trying to terminate the PPTP tunnel to is ?


Jeff
Old 12 November 2002 | 04:11 PM
  #4  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Jeff

Its a single dynaminc (standard PPP dial-up) external IP. VPN terminates on standard MS server behind a FW-1. Both the FW-1 and VPN server are my Dad's corporate infrastructure so no possibility to check/change configurations.

The *only* difference I can see between a connection that works (direct or via IOS F/W) and one that doesnt (via IPCop) is that IPCop routinely changes the source port. IOS doesn't. Same Client/Same destination/Same dial-up account/same config etc.

The TCP dest port 1723 control connection never seems to complete so I get no login prompt and it doesnt get anywhere near building the actual VPN tunnel.

Deano



Old 12 November 2002 | 04:45 PM
  #5  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Question

Doesn't MS VPN us GRE? does IPMASQ even forward that? I've done WinXP to PPTP server with my source port through a NAT that remapped the source port, no problem, I would be looking on the external interface to see if you can see any GRE packets at all.
Old 12 November 2002 | 04:49 PM
  #6  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

D'oh! lagged reply, ignore that is the TCP connection to 1723 doesn't even complete
Old 12 November 2002 | 05:01 PM
  #7  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

I would have thought that it would be simpler to use Secureremote or Secureclient on the client into the FW-1 rather than messing around with the nasty stuff that Microsoft claim as VPN software...but heh, each to their own.

I don't know enough about IPCop to give you an answer to this one....Sorry.

And I don't think that MS VPN uses GRE either.....


Jeff
Old 12 November 2002 | 05:10 PM
  #8  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Have you asked the question here ...

http://ipcop.hopto.org/



Jeff
Old 12 November 2002 | 05:10 PM
  #9  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

Sorry, it's specfically PPTP that uses GRE, not all MS VPN's
Old 12 November 2002 | 05:21 PM
  #10  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Does it ?? I thought that GRE was a specific Cisco thing....learn something new everyday !


Jeff
Old 12 November 2002 | 06:40 PM
  #11  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

PPTP uses an enhanced GRE (Generic Routing Encapsulation) mechanism to provide a flow- and congestion-controlled encapsulated datagram service for carrying PPP packets.
From here, but when did MS ever follow standards?
Old 12 November 2002 | 07:45 PM
  #12  
HHxx's Avatar
HHxx
Scooby Regular
 
Joined: Nov 2001
Posts: 2,576
Likes: 0
Lightbulb

Deano, does this help?
Old 13 November 2002 | 01:16 PM
  #13  
orbv's Avatar
orbv
Scooby Regular
 
Joined: Apr 2001
Posts: 1,103
Likes: 0
From: Hants
Arrow

ipchains always remaps the source port by default. Are you certain that the problem is the source port is not port 1723 or because the remote machine is sending back a connection on another predefinded port which is being rejected (like ftp protocol???).

There are a number of modules you can load to do special stuff (TM). I cant remember if there is a generic module or if you will need to write your own. The bundled modules are installed under /lib/modules/<kernelver>/????/ip_masq_?????

Will see what else I can find
Old 13 November 2002 | 01:23 PM
  #14  
orbv's Avatar
orbv
Scooby Regular
 
Joined: Apr 2001
Posts: 1,103
Likes: 0
From: Hants
Post

Does this help?

http://www.impsec.org/linux/masquerade/ip_masq_vpn.html
Old 13 November 2002 | 02:10 PM
  #15  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

I've done TCPdumps on the Ethernet and ppp0 interfaces and the control connection (source port 61000 to dest port 1723) never gets a single reply. - not even the first syn/ack. Like I said the same client talking to the same server but through an IOS based firewall works just fine

I'm 99% sure the "problem" is at the corprate firewall in that it is dropping the connection. however I have zero ability to change or check that. (its a smallish compnay who simply dont have the expertise to troublshoot or adjust their firewall just to let a single user do something different). So I need to a) adjust this end b) use something else. (RR may yet get a sale )

have read all the masquerade/vpn links I've checked and the pptp module is loaded and being used. I've even set up a VPN server at home and connected through the IPCop box to it. So its the interaction between the IPCop and the far end - of which I can only change this end.

Looks like I might be flogging a dead horse. I've tried Smoothwall 0.99 and that behaves the same. I'll give Smoothwall beta 2 a go tonight.

Deano
Old 13 November 2002 | 02:54 PM
  #16  
orbv's Avatar
orbv
Scooby Regular
 
Joined: Apr 2001
Posts: 1,103
Likes: 0
From: Hants
Post

Have you installed the patches from the link above? If not why not

If that does not fix the problem and the connection is going out on a different dst port I should be able to hack a quick module together to always allocate the same dest port.
Old 13 November 2002 | 04:14 PM
  #17  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Rob

I'm not into patching - I dont have a clue how to start IPCop is a cut down distro so I'd need to build a kernel on a matching full distro and move it i guess. Dest port (1723) is fine. Its the source port that I believe is causing the problem. I'm only going to spend so much time saving my Dad the cost of a decent small ISDN router . At the moment I think I might be able to blag another cisco 1603....

Many Thanks for the links though.

Deano
Old 13 November 2002 | 10:20 PM
  #18  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

Could try this
Old 13 November 2002 | 11:28 PM
  #19  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post

Have you had a butcher's here : http://www.quarkav.com/SmoothWallGPL/SWG_vpn_1.1.php


Personally I'm using a CP-FW1 client to make the connections, not the firewall itself.

Steve
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
f1_fan
Non Scooby Related
88
08 March 2014 02:57 AM
john banks
Non Scooby Related
88
01 February 2013 10:53 AM
Stueyb
Computer & Technology Related
3
24 August 2005 10:56 AM




All times are GMT +1. The time now is 03:26 PM.