Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: SOCKS w/ split DNS (was Re: DNS on firewall??)
From: Leo Plotkin <leo @ clinicom . com>
Date: Thu, 02 Mar 95 17:38:56 -0700
To: "Simon J. Gerraty" <sjg @ zen . void . oz . au>
Cc: firewalls @ GreatCircle . COM
In-reply-to: (Your message of Thu, 02 Mar 95 23:39:54 X.) <199503021239 . XAA16241 @ zen . void . oz . au>

"Simon J. Gerraty" <sjg @
 zen .
 void .
 oz .
 au> writes:
>Now (one day) I just have to modify SOCKS such that if the client can
>resolve a name it knows it can connect directly, otherwise it uses
>goes to sockd on the proxy host.  This would allow a single client to
>work inside and out, without unnecessary load on the proxy...

	It's been done.  There is a split DNS patch for cstc4.2beta as
	well as a stand alone Rgethostbyname.c on ftp.nec.com in
	/pub/security/socks.cstc.  I wrote my own version in about 15
	minutes before I heard about those.  

	The logic is very simple -- first use standard gethostbyname 
	to resolve hosts using a local policy (NIS, DNS, hosts, what 
	have you) and upon failure use the code already present in 
	Rconnect.c to check the Internet aware name server.

	SOCKS can be told to use 'direct' rather than 'sockd' connections
	using IP addresses & masks in socks.conf.

	--leo

	p.s. this subject has more to do with SOCKS than firewalls in
	general, and should probably move to the socks mailing list.


References:
Indexed By Date Previous: [no subject]
From: Abraham Lui <abraham @ hpindda . cup . hp . com>
Next: Re: your mail
From: "Bryan D. Boyle" <bdboyle @ maverick . erenj . com>
Indexed By Thread Previous: Re: DNS on firewall??
From: carson @ cs . columbia . edu
Next: Re[2]: DNS on firewall??
From: brian @ imcon . ilinx . com

Google
 
Search Internet Search www.greatcircle.com