BSD Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsBSD Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old October 9th, 2002, 04:26 PM
DD214 DD214 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2001
Location: USA
Posts: 33 DD214 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 8
How to allow gre through IPF?

My network is sitting behind an IPF/IPNAT firewall on a FreeBSD 4.3. I'm trying to connect to a remote Windows 2000 VPN server, but my connection is blocked by my firewall with the following log entry:

ipmon[112]: 14:22:10.738774 dc0 @0:2 b 192.168.168.124 -> 207.xxx.xxx.xxx PR gre len 20 (80) OUT

What do I need to add to my IPF rules to allow GRE in and out?

Last edited by DD214 : October 9th, 2002 at 04:54 PM.

Reply With Quote
  #2  
Old October 9th, 2002, 05:24 PM
DD214 DD214 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2001
Location: USA
Posts: 33 DD214 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 8
Never mind. All I had to do was add:

pass in quick proto gre from xxx.xxx.xxx.xxx/32 to xxx.xxx.xxx.xxx/32

pass out quick proto gre from xxx.xxx.xxx.xxx/32 to xxx.xxx.xxx.xxx/32

Reply With Quote
  #3  
Old October 9th, 2002, 05:41 PM
DD214 DD214 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2001
Location: USA
Posts: 33 DD214 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 8
OK. A new problem. Even with the rules set to allow any from any, it only allows one VPN connection at a time. I have to disconnect the currently connected user, reload ipnat, and make the new connection. Any idea how to get around this one?

Reply With Quote
  #4  
Old October 10th, 2002, 12:04 PM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Don't embarass yourself next time for asking a question that can be easily found in the FAQ.
Now please bookmark the Official IPF FAQ.

Reply With Quote
  #5  
Old October 11th, 2002, 04:26 PM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
i'm always afraid of asking questions here incase i over look something stupid, i'm sure u must have made at least 1 stupid comment given the number of posts u have.....as nobodies perfect
__________________

microsofts butterfly is their way off telling u their systems have a **** load of buggs
Advocating Linux Guide
Lesbian Linux
Great & Practical Computer Books

like the links?

Reply With Quote
  #6  
Old October 11th, 2002, 07:47 PM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
>> i'm always afraid of asking questions here incase i over look something stupid

In order to be successful keep in mind that asking question is always your last resort. Asking a question that when the answer can be easily found indicates that you haven't spent any time and effort on trying, which is a bad learning attitude in the first place, for relying on others for living.

Reply With Quote
  #7  
Old October 12th, 2002, 01:36 AM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
i have only asked a few questions

Reply With Quote
  #8  
Old October 12th, 2002, 11:58 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Good for you. And so far I haven't asked a single question anywhere, just because nothing is not STFW'able.

Reply With Quote
  #9  
Old October 12th, 2002, 12:29 PM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
never heard that acronym before

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsBSD Help > Howto allow allow gre through IPF?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway