[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

double PF setup.



I have a question that I thought best suited to this list.  If you think I should post it to misc instead let me know.

I am trying to setup the following.  (warning, ascii art follows:-)

               ( the net )
                    |
                    |
                    |      152.96.21.241 (fxp0)
              ------------
              | OBSD 3.2 |
          FW1 | PF / NAT |  
              ------------
                    | 10.10.1.241 (fxp1)
                    |                 -----------------
                    |-----------------| Suit-ware/IDS |
                    |                 -----------------
                    | 10.10.1.1 (fxp0)
          RT1 ------------                       -------------------
              | OBSD 3.2 | 10.5.20.2 (fxp5)      | Many hosts at   |
   -----------|    PF    |-----------------------| Regional offices|
   |10.2.0.0  ------------         ATM           -------------------
   | (fxp2)     |      |
   |            |      | 10.4.0.0 (fxp4)
   |            |      |                 --------------------------
   |            |      ------------------| Many web/email servers |
   |            |                        --------------------------
   |            | 10.3.1.0 (fxp3)
-----------     |     ---------------------------
|   many  |     |-----| Many staff workstations |
|   data  |           ---------------------------
| servers |       
-----------  
Hope this reads ok.  Basically we have one box running PF/NAT on the outside.  Network monitoring in the middle and then PF on a box in the middle doing routing and firewalling between private IP zones.

This is our new network layout.  We had been using public IPs on all machines and then using OBSD 2.9 with IPF as a transparent bridge.  I am in the process of changing to something like the above where I am using one box as the firewall then a second box as more of a router but someday I want to be able to use the power of PF to protect between my zones.  The reason for the two boxes is so the suit-ware/spy-ware/monitoring-crap, whatever you want to call it, can sit in the middle and get non-Natted IPs.  An IDS will also sit there.

My trouble is I can't seem to get from FW1 to RT1 and then on into my network.  I can ping just fine from 10.2.4.7, a data server, through RT1 to 10.5.20.2, a host in a regional office.  I feel like this must be in some ways a netmask issue but I feel like I need to have the open netmask (255.0.0.0) on the interfaces between FW1 and RT1 for a packet to be received by RT1 with the intent of forwarding on to 10.5.x.x.   

Details from FW1
bash-2.05b# more hostname.fxp0
inet 10.10.1.241 255.0.0.0 NONE

bash-2.05b# more pf.conf
nat on fxp0 from 10.0.0.0/8 to any -> 152.96.21.241
pass out all
pass in all

bash-2.05b# ping 10.5.20.2
PING 10.5.20.2 (10.5.20.2): 56 data bytes
ping: sendto: Host is down


Details from RT1:
bash-2.05b# more hostname.fxp0
inet 10.10.1.1 255.0.0.0 NONE

bash-2.05b# more hostname.fxp2
inet 10.2.4.241 255.255.0.0 NONE
 
bash-2.05b# more pf.conf
pass out all
pass in all

If I try to do a ping from FW1 to 10.5.20.2 I get this on RT1
tcpdump: listening on fxp0
23:18:32.296550 arp who-has 10.5.20.2 tell 10.10.1.241
23:18:33.301923 arp who-has 10.5.20.2 tell 10.10.1.241
23:18:34.311889 arp who-has 10.5.20.2 tell 10.10.1.241
23:18:35.321875 arp who-has 10.5.20.2 tell 10.10.1.241


If I do an: arp -s 10.5.20.2  00:08:02:b0:01:d2 on FW1 everything is cured.  ...but I have a thousand hosts so that is out of the question.  Is there any way to get RT1 to answer to arp requests for machines that are hanging off it's interfaces.

Should I just be running routed (zebra)?  Can I still use PF if I am using routed?

If I try to ping the outside world I see this in the tcpdump of fxp1 on FW1:
23:40:49.225667 arp who-has 10.5.20.2 tell 10.10.1.241

We have tried setting a static IP route using the route command on FW1 and either we didn't have the route right or it didn't work.

I can't find much about the Dup-to command in PF.  Would this be a better answer to my suit-ware problem?

Any ideas what I am doing wrong?  Need more information?

--ja

__________________________________________________________________
Try AOL and get 1045 hours FREE for 45 days!
http://free.aol.com/tryaolfree/index.adp?375380

Get AOL Instant Messenger 5.1 for FREE! Download Now!
http://aim.aol.com/aimnew/Aim/register.adp?promo=380455