Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: hybrid fw
From: sar <sar @ cynicism . com>
Date: Thu, 28 Aug 1997 01:12:50 -0500
To: firewalls @ greatcircle . com

At 04:36 PM 8/27/97 +0200, you wrote:
>I've got an ugly windows nt with a database and a web server
>
>I'm thinking about protecting it and its internal network
>with a linux. There will be a firewall, proxying the
>internal querys (www, etc) to the internet.
>
>The problem is that the nt holds cgi's written in visual
>basic. My intention is masquerading the network and
>adding rules in the linux box for letting access to
>the nt web server inside.
>
>
>internet ---- fw ------- internal net masqueraded
>			 nt web server masqueraded
>
>Is that possible ?
>
>Another idea is configure squid listening in the port 80
>of the firewall and passing the requests to the nt server
>inside. What about this ?
>

I havnt worked with linux ip masquerading for about 6 months so i dont know
if it has changed, but masquerading will not allow connections originating
from outside the firewall at all, do it does you no good if you want to run
daemons on a masqueraded machine. Some other network apps dont work well
with masquerading such as internet games or anything else where you would
want to listen for connections like powow and icq .. as of the last time I
used ip masquerading udp packets did not work as well. 

Indexed By Date Previous: Re: Crack-n-Hack olympics?
From: warpy <warpy @ null . net>
Next: FTP config with a firewall
From: Winnie Ang <WANG @ abacus . com . sg>
Indexed By Thread Previous: Re: hybrid fw
From: Peter da Silva <peter @ grendel . nmti . com>
Next: Re: -->Firewalls-Digest V6 #396
From: Da Vinci Assistant <-ASSIST- @ SCBSING . MHS . CompuServe . COM>

Google
 
Search Internet Search www.greatcircle.com