[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



Thanks,
Bob

> Best regards,

> Bob Toxen, CTO
> Fly-By-Day Consulting, Inc.
> d/b/a Horizon Network Security
> "Your expert in Firewalls, Virus and Spam Filters, VPNs,
> Network Monitoring, and Network Security consulting"

&gt; <a  rel="nofollow" href="http://www.verysecurelinux.com";>http://www.verysecurelinux.com</a>       [Network &amp; Linux/Unix Security Consulting]
&gt; <a  rel="nofollow" href="http://www.realworldlinuxsecurity.com";>http://www.realworldlinuxsecurity.com</a> [My 5* book: &quot;Real World Linux Security&quot;]
&gt; <a  rel="nofollow" href="http://www.verysecurelinux.com/sunset.html";>http://www.verysecurelinux.com/sunset.html</a>                    [Sunset Computer]
&gt; bob at verysecurelinux.com (e-mail)
&gt; +1 770-662-8321  (Office: 10am-6pm M-F US Eastern Time)
&gt; +1 404-216-5100  (Cell away from office)

&gt; My recent training and talks on Linux security include:
&gt;   at IBM's Linux Competency Center in New York City     on Mar.  06   2003
&gt;   at the Atlanta SecureWorld Expo in Atlanta            on May   22   2003
&gt;   at the Enterprise Linux Forum in Silicon Valley       on June  04   2003
&gt;   at Computer Associates' Atlanta Linux Security Summit on Sep.  16   2003
&gt;   in New Jersey                                         on Oct. 27-30 2003
&gt;   at Southeast Cybercrime Summit in Atlanta             on Mar.   4   2004
&gt;   at the FBI's Atlanta headquarters                     on Mar.  10   2004
&gt;   in Denver, CO                                         on Apr. 15-16 2004
&gt;   in New Jersey                                         on May. 25-26 2004
&gt;   at the Atlanta SecureWorld Expo in Atlanta            on May   27   2004
&gt;   in Denver, CO                                         on Jul. 12-13 2004
&gt;   at Linux World SF signing at Prentice Hall's booth    on Aug.  03   2004
&gt;   in Denver, CO                                         on Sep. 27-28 2004
&gt;   in Boston, MA                                         on Oct. 11-14 2004
&gt;   at Atlanta Unix Users Group                           on Nov.  01   2004
&gt;   in New Jersey                                         on Nov. 15-16 2004
&gt;   in Denver, CO                                         on 2/28-3/04  This Year

&gt; Author,
&gt; &quot;Real World Linux Security: Intrusion Detection, Prevention, and Recovery&quot;
&gt; 2nd Ed., Prentice Hall, (C) 2003, 848 pages, ISBN: 0130464562
&gt; Also available in Japanese, Chinese, Czech, and Polish.

&gt; If you spend more on coffee than on IT security, you will be hacked.
&gt; What's more, you deserve to be hacked.
&gt; -- White House cybersecurity adviser Richard Clarke

&gt; Public key available at <a  rel="nofollow" href="http://www.verysecurelinux.com/pubkey.txt";>http://www.verysecurelinux.com/pubkey.txt</a>, keyservers,
&gt;   and on the CD-ROM that comes sealed and attached to Real World Linux Security
&gt; pub  1024D/E3A1C540 2000-06-21 Bob Toxen &lt;book at realworldlinuxsecurity.com&gt;
&gt;      Key fingerprint = 30BA AA0A 31DD B68B 47C9  601E 96D3 533D E3A1 C540
&gt; sub  2048g/03FFCCB9 2000-06-21

&gt; On Tue, May 03, 2005 at 11:45:21PM -0400, James P. Kinney III wrote:
&gt; &gt; I have a new VPN I'm setting up and it just isn't working right. I'm
&gt; &gt; sure its a firewall issue but I'm stumped.
&gt; &gt; 
&gt; &gt; It's a net-to-net setup using OpenSwan on the gateways. From one end on
&gt; &gt; the LAN, I can ping another machine on the other LAN by IP address.
&gt; &gt; However, I _can't_ ping back the other way which is why I think it's a
&gt; &gt; firewall issue. I can see the traffic moving with tcpdump running on
&gt; &gt; multiple interfaces. I can see the ESP packets leaving and returning to
&gt; &gt; the external interfaces and I can the the decrypted packets entering the
&gt; &gt; LAN interfaces. I did some ping size tests and can get a max MTU of
&gt; &gt; 15236 which is bigger than normal.
&gt; &gt; 
&gt; &gt; I can't get jack else through the tunnel. No ssh, no http, no netbios,
&gt; &gt; no telnet, nada, bipcus. 
&gt; &gt; 
&gt; &gt; I set up a rule in iptables  on both ends to not NAT the traffic for the
&gt; &gt; other end (I don't expect I should be seeing any pings work otherwise).
&gt; &gt; 
&gt; &gt; I have both ends of the firewall so open I'm worried right now.
&gt; &gt; 
&gt; &gt; So I have developed a one way ping tunnel.  Argghhhhh.
&gt; &gt; -- 
&gt; &gt; James P. Kinney III          \Changing the mobile computing world/
&gt; &gt; CEO &amp; Director of Engineering \          one Linux user         /
&gt; &gt; Local Net Solutions,LLC        \           at a time.          /
&gt; &gt; 770-493-8244                    \.___________________________./
&gt; &gt; <a  rel="nofollow" href="http://www.localnetsolutions.com";>http://www.localnetsolutions.com</a>
&gt; &gt; 
&gt; &gt; GPG ID: 829C6CA7 James P. Kinney III (M.S. Physics)
&gt; &gt; &lt;jkinney at localnetsolutions.com&gt;
&gt; &gt; Fingerprint = 3C9E 6366 54FC A3FE BA4D 0659 6190 ADC3 829C 6CA7


</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00047" href="msg00047.html">[ale] VPN (s are) hell</a></strong>
<ul><li><em>From:</em> jkinney at localnetsolutions.com (James P. Kinney III)</li></ul></li>
<li><strong><a name="00271" href="msg00271.html">[ale] VPN (s are) hell</a></strong>
<ul><li><em>From:</em> transam at verysecurelinux.com (Bob Toxen)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00274.html">[ale] Window Chopping</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00276.html">[ale] Fwd: Federal Court Scraps Broadcast Flag!</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00271.html">[ale] VPN (s are) hell</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00049.html">[ale] Launchd from Apple</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00275"><strong>Date</strong></a></li>
<li><a href="threads.html#00275"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>