Great Circle Associates Firewalls
(June 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

From: Ken Hardy <ken @ bridge . com>
Date: Mon, 6 Jun 94 11:56:49 -0700
Apparently-to: <firewalls @ GreatCircle . COM>

>When using the CERN httpd as a proxy on the firewall, all connections
>to the proxy from within are to a single port.  The proxy makes the
>outbound connection to the proper port on the foreign system.
...
>If run in daemon mode, it has its own access control.  Unfortunately, it
>only lets you discriminate by domain or IP wildcard.  This means that I
>cannot explicitly disallow my external subnet except by explicitely
>allowing each individual internal subnet, which would be a real drag
>with our class B network and 8-bit subnet mask.

What I'm doing is to run two proxy servers, one on the firewall which only
allows access to a second, internal one. This internal one can then be
configured a little more easily, as one doesn't have to worry about explictly
disabling external access (since the firewall already takes care of that).

So far it seems to work okay, although there are some problems yet with
the way clients work with the proxy server (although I'm not convinced that
I'm not creating some problems of my own with the way I've configured things).
For instance, Mosaic 2.4 doesn't support the "no_proxy" mechanism, so all
requests end up going through the proxy server, even if you could get to the
resource directly.

Cheers,
Joe Meadows meadowsj @
 boeing .
 com or jem7049 @
 nobs .
 ca .
 boeing .
 com

Indexed By Date Previous: Re: tcp/ip training
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Next: Where to get http(d)
From: "Jay R. Jaeger" <dotjrj @ dot . state . wi . us>
Indexed By Thread Previous: Re: Yes! Subnet on the wire
From: reh @ cs . UMD . EDU (Richard Huddleston)
Next: Where to get http(d)
From: "Jay R. Jaeger" <dotjrj @ dot . state . wi . us>

Google
 
Search Internet Search www.greatcircle.com