Monday, August 8, 2022

Implement OCI IPSec Site to Site VPN

 

This post explains step by step the VPN IPSec tunnel configuration in Oracle Cloud Infrastructure and how we can leverage IPSec to establish the connectivity from On premises network to resources provisioned in Oracle Cloud Infrastructure. There are two types of modes supported by IPSec and this post, i have used Tunnel Mode and which is also supported by Oracle. The entire communication between the source and destination sites is encrypted, significantly lowering the chances of information theft.




My Source On premise addresses are as follows

Source CIDR:-10.0.0.0/29

Public Router Address:-140.238.226.118

Server IP Address:-10.0.0.0.146


OCI CIDR Range:-192.168.0.0/26



VCN Setup





Create DRG

Go to Networking>Customer Connectivity>Dynamic Routing gateways




Attach the DRG to VCN










Create Route Table




Destination is: On Premise CIDR


Create Security list and add the respective ingress/egress 






Create the Regional private Subnet









Create the CPE








Create an IPSec Connection to CPE














At this moment, the IPSec Status will be down.


Also, i have one compute instance running on private subnet. We can have Database or any services running on private subnet


Configuration on the On Premise host


Install libreswan in the on prem compute instance



[root@webserver opc]# yum install libreswan

[root@webserver opc]# ipsec version

Linux Libreswan 4.5 (XFRM) on 5.4.17-2136.307.3.1.el8uek.x86_64

[root@webserver opc]#


Turning Linux instance into a IP Router Now we will configure Libreswan and enable IP forwarding feature in order to turn our Linux Instance into a Router

[root@webserver opc]# cat /etc/sysctl.conf

# sysctl settings are defined through files in

# /usr/lib/sysctl.d/, /run/sysctl.d/, and /etc/sysctl.d/.

#

# Vendors settings live in /usr/lib/sysctl.d/.

# To override a whole file, create a new file with the same in

# /etc/sysctl.d/ and put new settings there. To override

# only specific settings, add a file with a lexically later

# name in /etc/sysctl.d/ and put new settings there.

#

# For more information, see sysctl.conf(5) and sysctl.d(5).


# Enable Panic on VMs on NMI trigger

kernel.unknown_nmi_panic = 1

net.ipv4.ip_forward=1

net.ipv4.conf.all.accept_redirects = 0

net.ipv4.conf.all.send_redirects = 0

net.ipv4.conf.default.send_redirects = 0

net.ipv4.conf.eth0.send_redirects = 0

net.ipv4.conf.default.accept_redirects = 0

net.ipv4.conf.eth0.accept_redirects = 0

net.ipv4.conf.default.accept_source_route = 0

net.ipv6.conf.default.accept_source_route = 0

net.ipv4.conf.all.accept_redirects = 0

net.ipv6.conf.all.accept_redirects = 0

net.ipv4.conf.default.accept_redirects = 0

net.ipv6.conf.default.accept_redirects = 0


[root@webserver opc]# vi /etc/ipsec.d/oci-ipsec.conf

conn oracle-tunnel-1

 left=10.0.0.146

 leftid=140.238.226.118 # See preceding note about 1-1 NAT device

 right=193.122.171.48

 authby=secret

 leftsubnet=10.0.0.0/29

 rightsubnet=192.168.0.0/28----VPN Address for tunnel

 auto=start

 mark=5/0xffffffff # Needs to be unique across all tunnels

 vti-interface=${vti1}

 vti-routing=yes

 ikev2=no # To use IKEv2, change to ikev2=insist

 ike=aes_cbc256-sha2_384;modp1536

 phase2alg=aes_gcm256;modp1536

 encapsulation=yes

 ikelifetime=28800s

 salifetime=3600s

conn oracle-tunnel-2

 left=10.0.0.146

 leftid=140.238.226.118 # See preceding note about 1-1 NAT device

 right=129.213.168.243-----VPN Address for Tunnel

 authby=secret

 leftsubnet=10.0.0.0/29

 rightsubnet=192.168.0.0/28

 auto=start

 mark=6/0xffffffff # Needs to be unique across all tunnels

 vti-interface=${vti2}

 vti-routing=yes

 ikev2=no # To use IKEv2, change to ikev2=insist

 ike=aes_cbc256-sha2_384;modp1536

 phase2alg=aes_gcm256;modp1536

 encapsulation=yes

 ikelifetime=28800s

 salifetime=3600s



Create ipsec secrets file


[root@webserver opc]# cat /etc/ipsec.d/oci-ipsec.secrets

140.238.226.118 193.122.171.48: PSK "fpLnW7HwiuEf5Fzu1PzHMVEVeFIszSUoaB4x2zgWtZyaNnk4kUrKZ3z5NIVFcWET"

140.238.226.118 129.213.168.243: PSK "0XczQpGij8GPr3GwPnXt9FSvefgD1UC4wgpxUCDufeSX7QBh6Ern0nWBRwuTUa59"

[root@webserver opc]#


Note: We can get the secret value from the view details section of the respective tunnels.


Restart the IPSec services

[root@webserver opc]#

 service ipsec restart


Verify the IPSec services

[root@webserver opc]# ipsec verify

Verifying installed system and configuration files

 

Version check and ipsec on-path                         [OK]

Libreswan 4.5 (XFRM) on 5.4.17-2136.307.3.1.el8uek.x86_64

Checking for IPsec support in kernel                    [OK]

 NETKEY: Testing XFRM related proc values

         ICMP default/send_redirects                    [OK]

         ICMP default/accept_redirects                  [OK]

         XFRM larval drop                               [OK]

Pluto ipsec.conf syntax                                 [OK]

Checking rp_filter                                      [ENABLED]

 /proc/sys/net/ipv4/conf/all/rp_filter                  [ENABLED]

  rp_filter is not fully aware of IPsec and should be disabled

Checking that pluto is running                          [OK]

 Pluto listening for IKE on udp 500                     [OK]

 Pluto listening for IKE/NAT-T on udp 4500              [OK]

 Pluto ipsec.secret syntax                              [OK]

Checking 'ip' command                                   [OK]

Checking 'iptables' command                             [OK]

Checking 'prelink' command does not interfere with FIPS [OK]

Checking for obsolete ipsec.conf options                [OK]

 

ipsec verify: encountered 3 errors - see 'man ipsec_verify' for help


Update the firewall rules

 

 

[root@webserver opc]# firewall-cmd --add-port=500/udp

success

[root@webserver opc]# firewall-cmd --add-port=4500/udp

success

[root@webserver opc]# firewall-cmd --runtime-to-permanent

success

[root@webserver opc]#


Update the Firewalls

[root@webserver opc]# firewall-cmd --add-port=500/udp

success

[root@webserver opc]# firewall-cmd --add-port=4500/udp

success

[root@webserver opc]# firewall-cmd --runtime-to-permanent

success

[root@webserver opc]#



Verify the tunnel status from the OCI Console







Now, you will be in a position to Ping and SSH to the compute instance running on OCI Private subnet.



References:-

Libreswan configuration: https://docs.cloud.oracle.com/iaas/Content/Network/Reference/libreswanCPE.htm?Highlight=shared%20secret

Oracle Cloud Infrastructure VPN Connect:https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/managingIPsec.html

 

 

 

  

 


 

 

 

 


Monday, July 18, 2022

OCI load balancer redirection using Routing Policies

In Layman terms, load balancers helps in distributing the requests to the backend servers based upon certain algorithms. OCI Load Balancers helps in achieving high availability and scalability. Based upon our requirement we can induce multiple policies and application level health checks in OCI Load Balancer. In this post, i am going to demonstrate how we can leverage routing policies to redirect requests to backend servers using certain conditions. If you want to know how to create a Load balancer, you can refer to my earlier post https://samappsdba.blogspot.com/2020/05/configuring-oci-load-balancer-for-ebs.html

 I have a webserver1 with Public IP:-X.X.X.65. This is registered under DNS as dumka.tk 
I have an another webserver2 with Public IP:-X.X.X.61. This is registered under DNS as dumka.ml




Now i will create the Load balancer





I will add the backend later









Load balancer will now be created.

Add the backends now






Create listener for two backends






Now create the hostnames






Edit the listener and add the respective hostnames








Now Define the Routing Policies










At last, add the Public IP of the Load balancer to the DNS Zones.


Perform the testing








There are many other advanced configurations which we can use with our OCI Load Balancer for which we can go through the Advanced OCI LB Concepts. You can also refer my earlier post OCI LB Redirection on how i had used Path Route set for Load balance Redirection. This post is all about how using one Network load balancer, we can serve multiple websites using hostname and Routing policies. Hope this post helps someone. Keep learning cloud.

Saturday, July 9, 2022

connect to Compute instance on Private Subnet using Public Load balancer OCI

 In this post, i am going to demonstrate on how we can connect to a VM Compute instance running on Private Subnet using a Network Load balancer. There are many ways available through which you can connect using Fast Connect, IPSec VPN or using Bastion Service which are beyond the scope for this post. The Oracle Cloud Infrastructure Flexible Network Load Balancing service (Network Load Balancer) provides automated traffic distribution from one entry point to multiple backend servers in your virtual cloud network (VCN). It operates at the connection level and load balances incoming client connections to healthy backend servers based on Layer 3/Layer 4 (IP protocol) data. The service offers a load balancer with your choice of a regional public or private IP address that is elastically scalable and scales up or down based on client traffic with no bandwidth configuration requirement.


Network Load Balancer provides the benefits of flow high availability, source and destination IP addresses, and port preservation. It is designed to handle volatile traffic patterns and millions of flows, offering high throughput while maintaining ultra low latency. Network load balancers have a default 1 million concurrent connection limit. Network Load Balancer is the ideal load balancing solution for latency sensitive workloads. For more information, you can refer to https://docs.oracle.com/enus/iaas/Content/NetworkLoadBalancer/overview.htm




Steps:- I have two subnets one is private and another one is public. The compute instance is created in Private Subnet and Network Load balancer is defined under Public subnet. Both the subnets have their respective Security lists and Route Tables. The compute instance will be accessible through SSH port 22.


Create a VCN






Create a NAT Gateway




Create  a Service gateway





Create Route Rule





Create a Security List 



192.168.0.8/30 is the CIDR for LB subnet


Create a Compute instance on private Subnet




Next, Create a the public Subnet which will host the LB.




Create the NSG for defining the ingress and egress of LB









Now Create the Network Load balancer







unselect Preserve Source IP





make Sure the health checks are passed






Now use the Public IP of the LB to connect to the private Compute instance using SSH






In this Blog Post, we looked into one of the easiest solution on how to connect to Compute instance running on Private Subnet. Using Network Load balancer, we can also connect to DB running on specific port, Windows RDP etc. I hope this post will help someone. Till then, enjoy learning Cloud.






















Tuesday, July 5, 2022

create oci iam user with least privilege

 The IAM service lets you control who has access to cloud resources. You can control what type of access a group of users has and to which specific resources. The service enables you to enforce the security principle of least privilege by default. New users aren’t allowed to perform actions on any resources until they’re granted the appropriate permissions. With the IAM service, you can use a single model for authentication and authorization across all OCI services. IAM makes it easy to manage access for organizations of all sizes—from one person working on a single project to large companies with many groups working on many projects at the same time—within a single account.

In my last post https://samappsdba.blogspot.com/2022/06/protect-accidental-termination-of-OCI-Compute-instance.html i had explained, how we can protect any compute instance from getting terminated by mistake. In this post, i will go through the demonstration on how we should create users when first time our instance is provisioned. Basically, when our instance is provisioned, we are given the tenancy administrator credentials. This user is the root user and it should not be used in our daily operations. Thus, when an instance is provisioned, the administrator should create separate user which can be used for day to day activities and this user should have the least privileges. 


Source-Oracle Documentations


In my tenancy, i have created one group



I will now create a user and assign the user to the group



User is assigned to group



Now once we reset the password for the user and set the email, the user is good to login to OCI. But will he/she be able to do anything. No, because the group, in which user has been assigned, doesn’t have any policies set

 We will get the below message




Thus, we will now create a policy and add the policy to the group






Now if the user try to login to the OCI Console, he/she will be able to see the instance now. The above policy will allow the user to work in only one compartment but under that specific compartment he/she can do all the work. If they go into other compartment in that case they cannot see the resources in other compartments. They will get an unauthorized error message

To further narrow down the scope in one specific compartment, i just want the user to see the compute instance and nothing else. In that case, my policy will be

Allow group REST_USERS to manage instance-family in compartment OCIPROF

Other example can be

Virtual-network-family

Database-family

Volume-family


I hope, this post gives an overview of how privileges are given to user and how least privileges are enforced to new user. Hope, this post helps someone. Till then happy learning cloud.