Sunday, July 19, 2020

Strongswan with public IP addresses traffic not going thru tunnel (UP)

We have a requirement to connect 2 sites with IPsec VPN and the instances (Test instances here) need to be addressed by their public IP addresses (thru VPN).

Test Ohio ============

Public: 3.134.112.49
Local: 172.31.40.148

The tunnel is up but traffic is not going thru. Any help will be much appreciated.

If I run a curl from Virginia Test instance I get this:

virginia-test ~]$ curl 3.134.112.49 -vvv * Rebuilt URL to: 3.134.112.49/ * Trying 3.134.112.49... * TCP_NODELAY set * connect to 3.134.112.49 port 80 failed: Connection timed out * Failed to connect to 3.134.112.49 port 80: Connection timed out * Closing connection 0 curl: (7) Failed to connect to 3.134.112.49 port 80: Connection timed out 

TCPDUMP on the Virginia VPN shows it's sending the SYN but never received the SYN-ACK from the peer. Here is the output (notice the SNAT is working):

 vpn-virginia ~]$ sudo tcpdump dst 3.134.112.49 -vvv tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes 18:27:03.651626 IP (tos 0x0, ttl 255, id 38717, offset 0, flags [DF], proto TCP (6), length 60) ip-172-31-72-19.ec2.internal.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x421c (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357116084 ecr 0,nop,wscale 7], length 0 18:27:03.651663 IP (tos 0x0, ttl 254, id 38717, offset 0, flags [DF], proto TCP (6), length 60) ec2-34-229-184-231.compute-1.amazonaws.com.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x5a82 (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357116084 ecr 0,nop,wscale 7], length 0 18:27:04.655967 IP (tos 0x0, ttl 255, id 38718, offset 0, flags [DF], proto TCP (6), length 60) ip-172-31-72-19.ec2.internal.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x3e2f (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357117089 ecr 0,nop,wscale 7], length 0 18:27:04.655997 IP (tos 0x0, ttl 254, id 38718, offset 0, flags [DF], proto TCP (6), length 60) ec2-34-229-184-231.compute-1.amazonaws.com.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x5695 (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357117089 ecr 0,nop,wscale 7], length 0 18:27:06.671970 IP (tos 0x0, ttl 255, id 38719, offset 0, flags [DF], proto TCP (6), length 60) ip-172-31-72-19.ec2.internal.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x364f (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357119105 ecr 0,nop,wscale 7], length 0 18:27:06.672000 IP (tos 0x0, ttl 254, id 38719, offset 0, flags [DF], proto TCP (6), length 60) ec2-34-229-184-231.compute-1.amazonaws.com.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x4eb5 (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357119105 ecr 0,nop,wscale 7], length 0 18:27:10.832008 IP (tos 0x0, ttl 255, id 38720, offset 0, flags [DF], proto TCP (6), length 60) ip-172-31-72-19.ec2.internal.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x260f (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357123265 ecr 0,nop,wscale 7], length 0 18:27:10.832039 IP (tos 0x0, ttl 254, id 38720, offset 0, flags [DF], proto TCP (6), length 60) ec2-34-229-184-231.compute-1.amazonaws.com.34090 > ec2-3-134-112-49.us-east-2.compute.amazonaws.com.http: Flags [S], cksum 0x3e75 (correct), seq 4182331314, win 26883, options [mss 8961,sackOK,TS val 2357123265 ecr 0,nop,wscale 7], length 0 

Here is the configuration:

Both VPN instances have Source/Destination Check Disabled.

Routing was changed on the subnet for the traffic to Test instances thru VPN instances.

Virginia VPN conf:

 Virginia VPN conf: config setup # strictcrlpolicy=yes # uniqueids = no conn reunite-rx-vpn type=tunnel authby=secret forceencaps=yes leftid=54.152.133.122 leftnexthop=%defaultroute leftsubnets={172.31.0.0/16, 34.229.184.231/32} leftauth=psk right=18.223.21.162 rightid=18.223.21.162 rightsubnets={3.134.112.49/32} rightauth=psk auto=start installpolicy=yes 

Ohio VPN conf:

Ohio VPN conf: config setup # strictcrlpolicy=yes # uniqueids = no conn reunite-rx-vpn type=tunnel authby=secret forceencaps=yes leftid=18.223.21.162 leftnexthop=%defaultroute leftsubnets={172.31.0.0/16, 3.134.112.49/32} leftauth=psk right=54.152.133.122 rightid=54.152.133.122 rightsubnets={34.229.184.231/32} rightauth=psk auto=start installpolicy=yes leftsourceip=3.134.112.49 rightsourceip=34.229.184.231 

Forwarding was enabled:

$ sudo cat /etc/sysctl.conf # sysctl settings are defined through files in # /usr/lib/sysctl.d/, /run/sysctl.d/, and /etc/sysctl.d/. # # Vendors settings live in /usr/lib/sysctl.d/. # To override a whole file, create a new file with the same in # /etc/sysctl.d/ and put new settings there. To override # only specific settings, add a file with a lexically later # name in /etc/sysctl.d/ and put new settings there. # # For more information, see sysctl.conf(5) and sysctl.d(5). net.ipv4.ip_forward = 1 net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.all.send_redirects = 0 net.ipv4.conf.default.rp_filter = 0 net.ipv4.conf.default.accept_source_route = 0 net.ipv4.conf.default.send_redirects = 0 net.ipv4.icmp_ignore_bogus_error_responses = 1 

IPTABLES:

VPN Virginia:

VPN Virginia $ sudo iptables-save # Generated by iptables-save v1.8.2 on Sun Jul 19 18:21:39 2020 *nat :PREROUTING ACCEPT [192:10204] :INPUT ACCEPT [24:1221] :OUTPUT ACCEPT [248:18959] :POSTROUTING ACCEPT [248:18959] -A PREROUTING -s 3.134.112.49/32 -d 34.229.184.231/32 -j DNAT --to-destination 172.31.72.19 -A POSTROUTING -s 172.31.0.0/16 -d 3.134.112.49/32 -j SNAT --to-source 34.229.184.231 COMMIT # Completed on Sun Jul 19 18:21:39 2020 # Generated by iptables-save v1.8.2 on Sun Jul 19 18:21:39 2020 *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -p udp -m udp --dport 500 -j ACCEPT -A INPUT -p udp -m udp --dport 4500 -j ACCEPT -A INPUT -p esp -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j ACCEPT -A FORWARD -j REJECT --reject-with icmp-host-prohibited -A OUTPUT -j ACCEPT COMMIT # Completed on Sun Jul 19 18:21:39 2020 

VPN Ohio:

VPN Ohio $ sudo iptables-save # Generated by iptables-save v1.8.2 on Sun Jul 19 18:21:01 2020 *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -p udp -m udp --dport 500 -j ACCEPT -A INPUT -p udp -m udp --dport 4500 -j ACCEPT -A INPUT -p esp -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j ACCEPT -A FORWARD -j REJECT --reject-with icmp-host-prohibited -A OUTPUT -j ACCEPT COMMIT # Completed on Sun Jul 19 18:21:01 2020 # Generated by iptables-save v1.8.2 on Sun Jul 19 18:21:01 2020 *nat :PREROUTING ACCEPT [251:11781] :INPUT ACCEPT [27:1485] :OUTPUT ACCEPT [245:18706] :POSTROUTING ACCEPT [245:18706] -A PREROUTING -s 34.229.184.231/32 -d 3.134.112.49/32 -j DNAT --to-destination 172.31.40.148 -A POSTROUTING -s 172.31.0.0/16 -d 34.229.184.231/32 -j SNAT --to-source 3.134.112.49 COMMIT # Completed on Sun Jul 19 18:21:01 2020 

XFRM policy:

VPN Virginia:

vpn-virginia ~]$ sudo ip xfrm policy src 0.0.0.0/0 dst 0.0.0.0/0 socket in priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket out priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket in priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket out priority 0 ptype main src ::/0 dst ::/0 socket in priority 0 ptype main src ::/0 dst ::/0 socket out priority 0 ptype main src ::/0 dst ::/0 socket in priority 0 ptype main src ::/0 dst ::/0 socket out priority 0 ptype main 

VPN Ohio:

vpn-ohio ~]$ sudo ip xfrm policy src 0.0.0.0/0 dst 0.0.0.0/0 socket in priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket out priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket in priority 0 ptype main src 0.0.0.0/0 dst 0.0.0.0/0 socket out priority 0 ptype main src ::/0 dst ::/0 socket in priority 0 ptype main src ::/0 dst ::/0 socket out priority 0 ptype main src ::/0 dst ::/0 socket in priority 0 ptype main src ::/0 dst ::/0 socket out priority 0 ptype main 


Why would a Router reply to all ARP requests?

A consumer grade router has been added to provide an internet connection to a professional network of equipment mainly using static IPs. I had been doing some remote checks with that router connected beside 2 other gear on a switch. Ping would sometimes work, sometimes not. I found out that the router replies to any ARP request sent on the network with a fixed MAC, probably to all ARP requests for IPs outside its DHCP range.

root@device:~# arping -c 1 10.192.20.1 ARPING 10.192.20.1 from 10.192.18.46 eth0 Unicast reply from 10.192.20.1 [C4:AD:34:B2:1D:71] 13.591ms Unicast reply from 10.192.20.1 [3C:37:86:AB:A2:BF] 691.303ms Sent 1 probes (1 broadcast(s)) Received 2 response(s) root@device:~# arping 10.192.20.5 ARPING 10.192.20.5 from 10.192.18.46 eth0 Unicast reply from 10.192.20.5 [C4:AD:34:B2:1D:7E] 4.303ms Unicast reply from 10.192.20.5 [3C:37:86:AB:A2:BF] 609.816ms Unicast reply from 10.192.20.5 [3C:37:86:AB:A2:BF] 4.173ms Unicast reply from 10.192.20.5 [3C:37:86:AB:A2:BF] 2.492ms Unicast reply from 10.192.20.5 [3C:37:86:AB:A2:BF] 1.141ms 

I can't find what this "feature" is really for, is it Dynamic ARP Inspection or poisoning to prevent spoofing? I have seen this behaviour already on a very tightly managed network but on there it the gateway would only reply if there's no other reply. Here I don't see how the network could reliably work with 2 replies to every ARP requests.

Thanks



Discord servers?

Does anyone know any networking discord servers?



Where to learn about running a network in a convention center?

Hello!

I work for a company that does live events and while I've never been involved in the networking aspect before I'm hoping to change that for when live events are back and I can contribute a bit more when I'm at these events.

Where should I start when trying to learn about what would be required to run a network at something like a convention center? Typically we get a DHCP drop from the IT staff and just run our own router into switches and hardline all of our computers which is all something I'm comfortable with.

​

I'd like to expand beyond that so I can be prepared for larger setups where our network is spanning different areas where we're running similar setups but with more connections and things like Access points rather than just wiring all computers.

​

We use Ubiquiti gear if that means anything!



CAT6a UTP or S/FTP in datacenter?

Hi all,

I've found some other threads regarding this (i.e. https://www.reddit.com/r/networking/comments/80nzde/shielded_patch_cables_in_rack_or_just_utp/ ) but since it does not match our case completely I'd like to ask to be sure...

We currently use CAT6a S/FTP cables to cable our network from the servers <-> switch within the same rack. All cables are mostly 2M tops, with perhaps a handful 5M cables.

We thought shielded = better, especially in a datacenter environment however compared to UTP cables the (lack of ) flexibility is quite a pain which makes cable management harder.

Looking online I see some mixed signals regarding UTP vs S/FTP cables so I'd like to ask for opinions to be sure:

  • The CAT6a cables are 2M to max. 5M
  • We do run 10G networking
  • We connect them between the servers and switches within the same rack.
  • There's quite a few network cables bundled together. We have 2x 48 port switches and most ports are connected.
  • The A/B power feeds for the servers are left/right so we cannot have all PSU cables on one side and network cables on the other side. This means some network cables will be close to the power cables. Unfortunately there isn't much space at the back of the rack to separate the PSU + network cables.


ISE Licensing sizing for Guest Portal

We have a Cisco ISE deployment for Guest Portal at a large hospital. The customer will be using Wifi for Guest Internet Access.

Can anyone share their experience on how to do licensing sizing of ISE for the guest portal deployment?



QoS still applicable in Leaf Spine architecture?

Either using ACI or VXLAN EVPN, is QoS still worth considering? Are there any real benefits to running QoS in Leaf spine architectures



Books about full broadband infrastructure

Hi,

I'm looking for books which explain a complete carrier network/infrastructure. I've read Telecom Basics by Lawrence Hart which explains components like DSLAM but is unfortunately outdated (2003).

So bascially I'm looking for a book which explains how broadband works from backbone to exchange offices to the distribution box/modem.

​

Thanks



VoIP related question: how do I call someone in another country over the internet and have it locally connect to a cell phone?

This would perhaps be best asked at r/VoIP, however I don’t have enough karma to post there. Sorry for bothering here, but I felt that someone might know what I’m looking for! Thanks.

I’m new to all of this. I’ve been reading about VoIP, ATA, PBX, PSTN, etc. and I’m sure what I’d like to achieve is possible, I just don’t know the name of the product I need.

There are three people involved here: myself, my associate, and my business partner.

Here’s the situation:

I’m in Europe and I have access to reliable internet. My associate is in East Africa and has very poor 3G (and barely 4G) connectivity.

Calls over data — of any kind — are hopeless. It doesn’t matter if it’s FaceTime Audio, WhatsApp, Skype, or anything else. Connections for my associate drop constantly.

I’d like to avoid racking up an expensive bill calling my associate through a traditional phone call. Receiving such a call would also be expensive for my associate so that’s not an option.

Now, I’m involved in building a small business network over in East Africa. In that location a fiber connection is available and it is generally reliable.

My business partner works at the location and has used a simple Wi-Fi AP to use the underlying fiber connection on an iPhone and FaceTime Audio calls come through perfectly.

Here’s the problem:

My associate moves around the country and rarely has a chance to be at the location with the business network setup.

My business partner however could be of use to setup something in the location, the question is: what do we need?

I’d like to be able to use my internet connection in Europe to call a <insert device here>, which would forward (or somehow connect) to my associate’s phone number over a traditional phone call.

Ideally, it would work in reverse: my associate calls the number associated with the <insert device here>, which then turns the call into a VoIP call or something similar, connecting to me here in Europe.

I don’t know the names of things or how they work. I thought maybe I could buy an Android phone for my business partner, who would connect it to the business network over Wi-Fi and then have some software do the magic (incoming VoIP is ”tunneled” into a traditional phone call to my associate’s mobile phone).

If I need to have my business partner swap out SIMs every now and then in the <insert device here>, that’s absolutely not a problem. Keep in mind only prepaid SIM cards are realistically available in the area.

What do I need and how does it work? Thank you a million for any pointers!



Saturday, July 18, 2020

We're an MSS and we have messed up customer firewalls rules

We run mss services wherein we have full control over the customer firewalls and all policy changes are done by us based on tickets opened by the customer.

The customers buy this service with the hope that the policies created by "experts" are going to be secure and tight without the dreaded - any any rules.

But lo and behold, all 10-15 of us have access to these customer firewalls and every time a ticket opens up, one of us makes the changes.

And its a mess! Multiple any-any rules allow traffic to all ports, fortunately, people do bother putting the source and destination addresses. I have no realized when a new ticket comes in now for a firewall, change the traffic is already allowed under some previous rule and you don't even need to do anything!

The bigger question is how to even maintain tight firewall rules, I am thinking a weekly fine-tuning of rules is a must and a reporting tool that can keep sending out emails every time traffic any any rule is created..how do yall do it?