Networking-Blog

My WordPress Blog

Linux Cisco Ipsec Vpn Configuration

Linux Cisco Config :

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds

Linux Ipsec Directory Conf :

conn commstest1
left= “Remote Peer Address”
leftnexthop= “Gateway Address”
leftsubnet= “Remote Subnet Address”
right= ”Local Wan Address”
rightsubnet= “Local Subnet Address”
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start

Set Keepalives :

dpdaction=restart
dpddelay=15
dpdtimeout=60

dpddelay
Set the delay (in seconds) between Dead Peer Dectection (RFC 3706) keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this connection (default 30 seconds). If dpdtimeout is set, but not dpddelay, dpddelay will be set to the default.
dpdtimeout
Set the length of time (in seconds) we will idle without hearing either an R_U_THERE poll from our peer, or an R_U_THERE_ACK reply. After this period has elapsed with no response and no traffic, we will declare the peer dead, and remove the SA (default 120 seconds). If dpddelay is set, but not dpdtimeout, dpdtimeout will be set to the default.
dpdaction
When a DPD enabled peer is declared dead, what action should be taken. hold (default) means the eroute will be put into %hold status, while clear means the eroute and SA with both be cleared. dpdaction=clear is really only usefull on the server of a Road Warrior config.

Set Domain-Name:

Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign.
If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause
the VPN initialization to fail.

rightid=@commstest.co.uk

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

e.g : Template :

conn <<SITE_NAME>>
left=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
leftnexthop=<<REMOTE_SITE_PUBLIC_ADDRESS>>
leftsubnet=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
right=<<REMOTE_SITE_PUBLIC_ADDRESS>>
rightnexthop=<<LOCAL_PHYSICAL_SERVER_PUBLIC_IP_ADDRESS>>
rightsubnet=<<SITE_LAN_NETWORK_ADD>/<SUBNET_MASK>
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60

Iptables Tcpdump

sudo tcpdump src 85.234.78.202
sudo tcpdump -n host 85.234.78.202
sudo tcpdump -i eth0 -n host 194.62.125.132 -vv
sudo tcpdump -nn -i eth3 host 10.11.254.216 and host 10.11.1.249
sudo tcpdump -nn -i eth2 -E commsvpn host 10.11.254.216 and host 10.11.1.249
sudo tcpdump -nn -i eth2 host 10.11.254.216 and host 213.122.172.146

sudo tcpdump -i eth1 | grep host-1.1.1.1.comms.uk.net
sudo tcpdump -i eth1 | grep 192.168.17.78
sudo tcpdump -i eth1 | grep webmail

sudo tcpdump -i eth0 src 82.109.100.227
sudo tcpdump -i eth1 port 1801
sudo tcpdump -nn -i eth1 port 1801
sudo tcpdump -i eth1.26 host 172.16.30.10 and net 192.168.0.0/16

Packet Sniffing on Destination Ip Address
(80.74.16.249 is a web server, All ip addresses destined for webserver)
sudo tcpdump -i eth0 -vv dst 80.74.16.249 and port 81

sudo tail -f /var/log/messages
sudo cat /var/log/messages | grep DST=25

sudo ifconfig
ping 10.11.1.253 -I eth3

Additional Commands :
tcpdump udp port 2055
!
service ntop status
!
Then, make sure it is listening on the correct port :
netstat -an | grep 2055

Iptables Show Commands

sudo iptables -nvL
sudo iptables -t nat -vnL unfiltered_web
sudo iptables -t nat -vnL PREROUTING
sudo iptables -vnL FORWARD
!

sudo iptables -t nat -vnL unfiltered_web –line-numbers

!
sudo tail -f /var/log/messages

Added a line in the input chain to allow access

iptables -I INPUT 9 -p tcp -s 93.97.239.164/31 -d 85.234.71.225 –dport 3389 -j ACCEPT
iptables -R INPUT 9 -p tcp -s 93.97.239.164/31 -d 85.234.71.225 –dport 3389 -j ACCEPT
This should give access to the RDP session.

iptables -I  = Insert Rule
iptables -R = Replace Rule

Delete an Entry :

sudo iptables -D INPUT 9

Monitor iptables :

watch sudo iptables -nvL INPUT
watch sudo iptables -nvL OUTPUT
watch sudo iptables -nvL FORWARD

Iptables PreRouting Rule

sudo iptables -t nat -vnL
sudo iptables -t nat -vnL –line-numbers
!

Port Forward From A Static Public Ip. Port Translation from 4000 to 3389.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_int -p tcp -m tcp –dport 4000 -j DNAT –to-destination 10.11.254.4:3389

Port Forward From Any Public Ip.
iptables -t nat -I PREROUTING -d internal_lan_int -p tcp -m tcp –dport 25 -j DNAT –to-destination 10.11.254.250:25

Port Forward From A Static Public Ip to Internal Lan Webserver.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_ip -p tcp -m tcp –dport 80 -j ACCEPT

Port Forward From A Static Public Ip. Port Redirection from 80 to 8080.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_ip -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
Port Forward From Any Public Ip. Port Redirection from 80 to 8080.
iptables -t nat -I PREROUTING -s internal_lan_ip -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

Drop Port Forward Traffic from Public Ip.
iptables -t nat -I PREROUTING -s public_ip -j DROP

Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201
iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201

To Delete a rule :
sudo iptables -t nat -D PREROUTING 14

E.G :

Prerouting

If you have a server on your internal network that you want make available externally,
you can use the -j DNAT target of the PREROUTING chain in NAT to specify a
destination IP address and port where incoming packets requesting a connection to your
internal service can be forwarded.


use the following command
:
This rule specifies that the nat table use the built-in PREROUTING chain to
forward incoming HTTP requests exclusively to the listed destination IP address of 172.31.0.23.

For example, if you want to forward incoming HTTP requests to your dedicated
Apache HTTP Server at 172.31.0.23,

iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to 172.31.0.23:80

If you have a default policy of DROP in your FORWARD chain, you must append a rule to
forward all incoming HTTP requests so that destination NAT routing is possible.

To do this, use the following command:
This rule forwards all incoming HTTP requests from the firewall to the intended destination;
the Apache HTTP Server behind the firewall
.

iptables -A FORWARD -i eth0 -p tcp --dport 80 -d 172.31.0.23 -j ACCEPT

Iptables Forward Rule

sudo iptables -I FORWARD -s 194.62.0.0/255.255.0.0 -d 192.168.0.0/255.255.0.0 -j ACCEPT
sudo iptables -I FORWARD -s 192.168.0.0/255.255.0.0 -d 194.62.0.0/255.255.0.0 -j ACCEPT
!
!
sudo iptables -I FORWARD -s 172.16.167.0/255.255.255.0 -d 217.160.16.191 -p tcp -m tcp –dport 25 -j ACCEPT
sudo iptables -I FORWARD -s 172.16.167.0/255.255.255.0 -d 217.77.181.120 -p tcp -m tcp –dport 25 -j ACCEPT

sudo iptables -I FORWARD 5 -s 172.24.15.64/255.255.255.192 -j ACCEPT

Iptables Unfiltered Web Rule

Allows Incoming HTTP requests on Port Tcp 80 to jump to the unfiltered_web chain :
sudo iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web

Allows HTTP traffic to permit port 80 traffic or to jump to filtered_web chain :
sudo iptables -A unfiltered_web -s 80.74.22.132 -j ACCEPT
sudo iptables -A unfiltered_web -j filtered_web

Allows HTTP traffic on filtered_web chain to get redirected to the content filter server
listening on tcp port 8080
:

sudo iptables -A filtered_web -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

show commands :

sudo iptables -t nat -vnL unfiltered_web –line-numbers

Scenerio :

This server has SSL enabled. Server ip address 10.10.1.91
Dansguardian content filter only filters http port 80 traffic.

In order to allow an internal vpn subnet / host address to access web server
on port 80.

We need to complete the following below :

Configure Port forward :

iptables -t nat -I PREROUTING -d 1.1.1.1 -p tcp -m multiport –dports 80,443 -j DNAT –to-destination 10.10.1.91

Configure rule to allow subnet 172.17.1.1/24 to webserver within the vpn on port 80

iptables -t nat -I unfiltered_web 1 -s 172.17.1.0/24 -d 10.10.1.91 -m tcp -p tcp –dport 80 -j ACCEPT

Complete…

This rule allows all http port 80 traffic to be redirected to proxy port 8080 destined
to the dansguardian content filter on 172.16.150.248.

All http traffic will get redirect to the content filter server listening on tcp port 8080

iptables -I filtered_web -p tcp -m tcp —dport 80 -j DNAT –to-destination 172.16.150.248:8080


Quick Summary :

sudo iptables -t nat -I PREROUTING 1 -i eth 0 – 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -i eth0 -s 10.10.34.12/32 -j ACCEPT
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!

sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

Linux Zyxel Ipsec VPN Configuration

Zyxel Router Linux Config.

Phase 1 (IKE) = Lifetime   8Hrs
Phase 2 (IPSEC) = Keylife 24hrs

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds
1440     = 24hrs  = Minutes
480       = 8hrs     = Minutes

Linux Ipsec Directory Conf :

conn commtest
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left= “Remote Peer Address”
leftsubnet= “Remote Subnet Address”
right=”Local Wan Address”
rightsubnet= “Local Subnet Address”
keyingtries=3
pfs=yes
rekey=yes
auto=start
keyexchange=ike
ikelifetime=8h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

Rereadsecrets Command Forces OpenSWAN to reload the secrets from the ipsec.secrets file

sudo ipsec auto –rereadsecrets

Iptables Save

Saving iptables

If you were to reboot your machine right now, your iptables configuration would disappear.
Rather than type this each time you reboot, however, you can save the configuration,
and have it start up automatically.

Directory Path :

GENTOO = /var/lib/iptables/rules-save
OPENSWAN = /etc/sysconfig/iptables

To save the configuration, you can use

iptables-save
iptables-restore

Save your firewall rules to a file

iptables-save >/etc/iptables.rules

Restore Iptables:

iptables-restore < /etc/iptables.rules