Linux XVNC Listening Port Service Command
Run this command via ssh or terminal window to have Xvnc to start listening
on tcp port 5900 & Http port tcp 5800.
x11vnc -forever -usepw -httpdir /usr/share/vnc-java/ -httpport 5800
Run this command via ssh or terminal window to have Xvnc to start listening
on tcp port 5900 & Http port tcp 5800.
x11vnc -forever -usepw -httpdir /usr/share/vnc-java/ -httpport 5800
nat (inside) 1 0.0.0.0 0.0.0.0 is correct for NATing all internal traffic.
!
dhcpd auto_config outside if your ISP is giving the ASA an IP with DHCP.
As I am sure many of you who have ever worked with a Cisco firewall know,
ICMP is not allowed through the firewall by default. If you are just configuring the device,
this can make it very difficult to troubleshoot connectivity issues.
Thankfully, there are several ways to get around this.
Solution 1: Use access-lists to allow pings from inside/DMZ to the outside.
To allow pinging from the inside to the outside interfaces, you will need to configure an access-list for the outside interface.
Then apply the access-list to the outside interface.
This will allow only ping. If you would like to allow trace route, you will also need to allow time-exceeded.
Solution 2: Use access-list to allow ping and trace route from the internet to your dmz/inside servers.
To do this, we are going to build off of what we did above, so you should already have this in the config.
Now all we need to do is allow echo into the network.
Even though we are allowing icmp, we still need to have a static mapping to allow the packets to reach the DMZ.
Of course, you will need to have a static mapping for every server you want to have reachable from the internet.
Solution 3: This is a bit more complex, but will allow higher security level interfaces to ping/trace route lower security level interfaces without the use of access-lists. To do this, we will tell the ASA to inspect icmp in a service policy. If you are using a ASA, you should have a default policy in the base config called global_policy.
global_policy:
To add icmp inspection.
Create Phase 1 Policy :
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600
Create Transform-set for Encryption being used :
crypto ipsec transform-set minimal esp-null esp-md5-hmac
crypto ipsec transform-set secure esp-3des esp-md5-hmac
Create a nonat access-list :
access-list nonat permit ip 172.31.0.0 255.255.0.0 192.168.0.0 255.255.0.0
Create Access-list for allowed network Source & Destination :
access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0
Create Crypto Map :
crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
Create a Preshared-Key :
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255
Assign Crypto Map to Interface :
crypto map armadillo interface outside
isakmp enable outside
Allow IPSEC traffic into Pix from public facing interface :
sysopt connection permit-ipsec
Summarize rule for each additional vpn to be added :
access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.178.0 255.255.255.0
crypto map armadillo 880 ipsec-isakmp
crypto map armadillo 880 match address 880
crypto map armadillo 880 set peer 2.2.2.2
crypto map armadillo 880 set transform-set secure
isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255
To remove a VPN addittional policy :
no access-list nonat permit ip 172.31.0.0 255.255.0.0
192.168.0.0 255.255.0.0
!
no access-list 880 permit ip 172.31.0.0 255.255.0.0
192.168.166.0 255.255.255.0
!
no crypto map armadillo 880
!
no isakmp key commsvpn address 2.2.2.2 netmask 255.255.255.255
Cisco 857w allows only 1 broadcast configurable SSID.
See the exact configuration set out below :
Keep in mind this is what is needed for the wireless part of the configuration and inside
NAT statement via Route-Maps is not included.
dot11 ssid COMMS
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 test
interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid test
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Vlan1
description Bind_to_BVI1_Interface
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
!
interface BVI1
description $ES_LAN$
ip address 192.168.194.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
ip dns server
ip nat inside source route-map NAT interface Dialer0 overload
!
route-map NAT permit 10
match ip address name NAT_ACL
!
ip access-list extended NAT_ACL
permit ip 192.168.194.0.0 0.0.0.255 any
!
bridge 1 protocol ieee
bridge 1 route ip
To make sure our traffic gets routed to the other end of the tunnel, create a file called ip-up in /etc/ppp and add the following lines to this file:
#!/bin/sh
/sbin/route add -net REMOTE-NET-IP netmask REMOTE-NET-MASK dev ppp
eg :
route add -net 10.20.254.248 netmask 255.255.255.248 dev ppp0
In which you have to replace the IP-address and the mask with those of the subnet on the other end of the tunnel. If there is no network on the other side, but just the pptp server, you can use -host instead of -net. When your done, save the file and make it executable:
chmod +x /etc/ppp/ip-up
Now that all is set up we can start the tunnel:
yum install pptpd
apt-get pptpd
At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the
PPTP port (1723) on the machine:
[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd: [ OK ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.
3 configuration files we need to worrry about. They are :
/etc/pptpd.conf
/etc/ppp/options.pptpd
/etc/sysctl.conf
!
Let’s start with /etc/pptpd.conf
edit file :
nano /etc/pptpd.conf
# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options
# Use linux client profile:
#option /etc/ppp/LXpptpd-options
# Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600
# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253
!
Now, on to /etc/ppp/options.pptpd
As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt. Below are the options that you actually care about:
name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490 ## may help your linux client from disconnecting
!
Lastly, /etc/sysctl.conf :
Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.
net.ipv4.ip_forward = 1
Setting up Users :
The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets
# client server secret IP addresses
rich pptpd apassword 80.40.0.0/13
geoff pptpd apassword 212.219.0.0/14
Test and Troubleshoot :
/etc/init.d/pptpd stop
/etc/init.d/pptpd start
Sumarize Firewall Rules :
1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any.