Great Circle Associates Firewalls
(April 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: WWW, Wais and Gopher proxies
From: Ian Dunkin <imd1707 @ ggr . co . uk>
Date: Fri, 22 Apr 1994 21:23:52 +0100 (BST)
To: Ken Hardy <ken @ bridge . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199404221613 . AA00397 @ racerx . bridge . com>
Reply-to: Ian Dunkin <imd1707 @ ggr . co . uk>

On Fri, 22 Apr 1994, Ken Hardy wrote:

> 2.  We cannot seem to get to an internal HTTP server when using the
>     proxy on the firewall.  It seems that the request should go to the
>     proxy which will resolve the hostname to the internal host and
>     forward the request there, handle the response, etc.; it shouldn't
>     differentiate between internal & external servers

Silly question:  Are you sure it's not simply that your firewall
configuration (eg router filters) is such that connections cannot be
initiated inwards from the firewall system back into your internal net?
 -- this would not be an unusual setup.  In which case, although the httpd
gets and tries to fulfil a request to an internal resource, it physically
cannot get back to it. 

The CERN WWW people have been talking (www-talk list) about a mechanism to
allow the proxy redirections on the client to differentiate between those
to directly accessible nets and those which must be proxied; but this is
not there yet. 

This problem of inward access back to internal servers was one of the
reasons behind adding SOCKS to the CERN httpd; another was simply not
wanting to run the big lump of code that is an httpd on a firewall bastion
system at _all_.  Having SOCKS in the proxy httpd allows it to run on your
_internal_ net; and SOCKS already has knowledge of which nets are directly
reachable. 

    I.

--
Ian Dunkin <imd1707 @
 ggr .
 co .
 uk>
--


References:
Indexed By Date Previous: Course on Innernet Security isues.
From: Neil Kochar <nkochar @ apnetadmin . gta . doc . ca>
Next: Re: WWW, Wais and Gopher proxies
From: Ken Hardy <ken @ bridge . com>
Indexed By Thread Previous: Re: WWW, Wais and Gopher proxies
From: Ken Hardy <ken @ bridge . com>
Next: Re: WWW, Wais and Gopher proxies
From: Ken Hardy <ken @ bridge . com>

Google
 
Search Internet Search www.greatcircle.com