Menu ▾ ▴

#254 Subnet of Supernet on different IF trips address anti-spoof

open
nobody
5
2012-09-14
2012-04-21
No

If one creates a network on a PEP which is a subnet on an existing network and it uses a different interface, its packets are improperly blocked by the address anti-spoof rules for the supernet. We found this when setting up and IPSec/L2TP VPN. The existing network was 192.168.15.0/24 on bond0. The L2TP users were assigned addresses out of 192.168.15.192/27 on interface ppp0. The was an existing anti-spoof rule of:
DROP all -- !bond0 * 192.168.15.0/24 0.0.0.0/0
The new network appended a rule:
DROP all -- !ppp+ * 192.168.15.192/27 0.0.0.0/0
Packets from 192.168.15.192/27 on ppp+ hit the bond0 rule first and were dropped.
We could address this either of two ways:
1) We check for supernets and, if there are any, we delete the supernet address anti-spoof rule, create the subnet rule, and then recreate the supernet rule so that it is processed after the subnet. That seems a bit kludgy and could create a problem if there is a legitimate reason for a packet from the subnet to be on the supernet interface. I'm not sure if there is a justifiable such case.
2) We could create a separate chain for address anti-spoof rules, change the rules to RETURN rules rather than DROP and then have a drop all at the end. On first look, this seems to be the better approach.

Discussion


Log in to post a comment.