Displaying 20 results from an estimated 2000 matches similar to: "Help! Martians invading through IPSec. :-)"
2004 Dec 30
5
Proxy Arp
Hello Tom,
I have successfully configured proxy arp subnettinng on my network with
three hosts in a Dmz.
And it works great. (using proxyarp in interfaces) I also tryed this on
network below same trouble.
However for this network below I have tryed to configure one host in a
Dmz (using /etc/shorewall/proxyarp) which works and comes up after I set it
up
and clear Isp''s arp
2012 May 16
1
ARP requests are interpreted as a martian
Shorewall 4.5.1.1
I have 5 interfaces on a centos box, the first two are internal on two
different subnets, the next two are two different ISP''s and the last one
is a private network for testing and administration. The second internal
subnet (eth1) is rejecting all the arp requests to it and I get the
following in the log files ever second or two -
May 16 05:28:54 services kernel:
2004 Dec 11
5
Problem report -- shorewall 1.4
Hello list,
I wish to report a problem with openvpn tunnels.
Synopsis: Despite adding policies to the shorewall policy file, I have
to add extra rules to allow the UDP port 5000 packets to get through.
I have used no particular setup guide.
I believe this problem goes away with shorewall 2.0.9, as I have
implemented openvpn with that version on a different machine, and I see
no UDP:5000 packet
2004 Aug 12
0
Advanced Routing and FreeSwan
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
I''m trying to setup a central IPSEC-Gateway with several ipsec tunnels.
Some are to be routed over one leased line, some over the other leased
line. Both leased lines have their own public ip adress.
The setup looks kinda like this:
eth1(ipsec0)--ISP0--Internet--eth1-Linux1-eth0--Subnet1
/
2008 Feb 29
5
shorewall-perl not handling "logmartians" correctly
I''ve set up a simple 2-interface Linux router using shorewall-perl 4.0.8
(and upgraded to 4.0.9). Everything works flawlessly. One small
exception I have noticed (since I''m a new shorewall user I
assume this is probably an error on my part).
1. Problem:
With no "logmartians" entries in /etc/shorewall/interfaces,
shorewall-perl sets
2004 Feb 20
1
{Spam} shorewall-vpn with cisco router(vlan) problem
Hi everyone. I am so baffled by the following problem:
Office 1 is using ADSL and it is building a VPN tunnel with IPSEC to
Office 2. Both ends are using shorewall/freeswan firewalls.
Diagram:
Office1 fw --- VPN TUNNEL --- Office2 fw --- cisco router ----- VLANS
|
DMZ
Office 1 has the following interfaces:
2: eth0:
2010 Nov 25
13
VLAN martians
I''m playing around with VLAN''s and I have a VLAN capable (layer 2) smart
switch. I see a steady stream of martians in the logfile if I have the
routefilter option set on the loc zone interfaces in
/etc/shorewall/interfaces. I have two interfaces in the loc zone, eth1
and vlan2 respectively. vlan2 is an 802.1q trunk going towards the switch.
Is this the expected behavior in
2006 May 03
5
SNAT on IPSEC tunnel with kernel 2.6/KAME tools?
Hi,
Could not conceive an working set-up for an IPSEC VPN made with racoon/setkey
on which I have one address on my side acting as an SNAT router for all
traffic from my network to a network segment on the far side.
my network --- my gateway ---------------------- remote network
10.0.0.0/24 - 10.0.0.1 (10.253.0.2) -- tunnel - 192.168.0.0/22
All traffic starts on my side, so if I can
2004 Nov 26
5
Martian sources...
We are seeing the following in our logs:
Nov 25 16:21:41 fw kernel: martian source 139.142.66.253 from
10.0.0.199, on dev eth0
Nov 25 16:21:41 fw kernel: ll header:
00:a0:c9:60:0e:b2:00:02:7e:21:0e:dc:08:00
00:a0:c9:60:0e:b2 is the mac of our firewall interface on IP
139.142.66.253.
00:02:7e:21:0e:dc is the mac of our Cisco router on IP 10.0.0.1
10.0.0.199 is a Cisco switch - we have about
2005 Jan 09
22
Dmz
Hello Tom,
I am not sure if you can help with this but I am at my wits end.
If you hit this site and do a force refresh (ctrl + F5) the site will time
out
and lose connections.
Do the same on port 443 and it does not time out???
The web site I am reffering to is www.tituswill.com
I think the only problem is port 80.
Do you have any idea how to diagnose this I have sent a dump
of just
2005 Mar 31
3
Multiple subnet question
Hi All,
I just added a second subnet and thought I had read all the relevant
FAQ''s and had set things up properly, but a few odd things are
happening.
ZONES:
net Net Internet
loc Local Local networks 192.168
loc2 Local Local networks 10.151
ppp PPP PPP Dial-in
rw RoadWarriors Road Warriors
rw2 RoadWarriors Road
2012 Jul 31
11
A lot of kernel martian source messages in /var/log/messages
Hi all:
I see a lot of the errors below in /var/log/messages on my firewall:
Aug 1 00:47:44 munin kernel: [109008.257109] martian source 192.168.1.5 from 127.0.0.1, on dev eth1
Aug 1 00:48:44 munin kernel: [109068.257384] martian source 192.168.1.5 from 127.0.0.1, on dev eth1
Aug 1 00:49:44 munin kernel: [109128.257509] martian source 192.168.1.5 from 127.0.0.1, on dev eth1
Aug 1 00:50:44
2007 Feb 10
0
mutliple default routes, rp_filter and martians
I have a theory on the cause of a problem but it is still only a theory.
I wonder if anyone here can confirm.
I have a multi-isp configuration with a multi-path default route to each
ISP, equally weighted.
I am seeing, periodically, traffic dropped due to martian detection and
errors logged on inbound traffic, but at other times, that same exact
traffic will be allowed, no errors.
My
2004 Oct 29
8
No entries in the syslog, even though the LOG chains show counts
I have obviously done something on my system to cause it to no longer
show Shorewall log entries in the syslogs, but for the life of me I
can''t figure out what. Let me first give you some details about my
config which will hopefully show why I think logging should be working,
and perhaps you can tell me why it''s not.
I am using version 2.0.9 from the debian sarge package
2007 Feb 09
26
transient "martian source ..." errors
Hi All,
As you probably all know :-) I''m trying to do the multi-isp thing. I''ve
resolved my last issue with the route_rules as suggested by Tom and
Jerry suggested.
Lately I have been seeing "transient" (I say transient because the
problem will persist for a while and then magically clear itself up some
number of minutes later) situations where my gateway will log:
2014 Sep 17
2
lost packets - Bond
Guys, good afternoon
I'm using in my bond interfaces as active backup, in theory, should assume an
interface (or work) only when another interface is down.
But I'm just lost packets on the interface that is not being used and is generating
packet loss on bond.
What can that be?
Follow my settings bond
[root at xxxxx ~]# ifconfig bond0 ; ifconfig eth0 ; ifconfig eth1
bond0
2003 Mar 14
5
ipsec for linux 2.4 eventually made easy?!
hi there,
I just wanted to share a recent discovery I did on how to setup a secure
VPN implementation for linux 2.4.x (I''m using 2.4.20 but it should be
working, as far as documentation states, for > 2.4.18) without using
FreeS/WAN.
The tool (ipsec_tunnel: http://ringstrom.mine.nu/ipsec_tunnel/, by
Tobias Ringström) is a kernel module based on ipip and ip_gre. It uses
CyptoAPI to
2008 Feb 25
7
kernel: martian
Hi,
I have a setup problem with Shorewall 4.0.6, which I can''t figure out why
it is not working:
I want to install a fireall with 2 extra interfaces :
- My serv ("dmz") zone is a /28 subnet behind eth1, with a small number of SUN
servers (IPs between ABC.DEF.75.1 and .13), one of which is a DHCP server for
the 75 subnet.
- The loc zone are PCs in the 75 subnet behind eth2
2004 Dec 04
7
vpn-zone wide open
Hello!
I am using shorewall shorewall-2.0.11-1 on fedora core2
(iptables-1.2.9-95.7). My box has 2 physical nic´s plus one virt. ipsec
interface for a freeswan-vpn connection.
A few days ago, portsentry spit out a lot of connections from windows
clients (port 135, 445). Ooops.
I review my shorewall settings but could not find a mistake. So I took a
win-client and established a second
2013 Nov 21
14
openvpn restart fails with dual entry in conntrack and wrong sourceport
the establishment of an openvpn link sometimes fails.
I tracked it down to network traffic with wrong Sourceport in the answer
packet (should be 1300 not 1024):
2 1.119309000 aaa.185.165 bbb.162.192 UDP 58 Source port: 1300
Destination port: 1300
3 1.119446000 bbb.162.192 aaa.185.165 UDP 66 Source port: 1024
Destination port: 1300
and a collateral entry in the connection tracking table