1 |
mRyOuNg schrieb: |
2 |
> Andreas Herrmann wrote: |
3 |
>> Hi there, |
4 |
>> |
5 |
>> I want to setup a gateway / firewall solution with Gentoo. The network |
6 |
>> has following structure: |
7 |
>> |
8 |
>> Several host (host[1,...,x].domain.net) are defined within the DNS and |
9 |
>> all of them have the same A-Record with the IP 1.2.3.4 |
10 |
>> The gateway is listening on its external network interface with the IP |
11 |
>> 1.2.3.4 and has an internal interface with a private subnet |
12 |
>> (192.168.0.0/24). The hosts (host[1,...,x].) are addressed in this |
13 |
>> subnet. |
14 |
>> |
15 |
>> How can it be solved, that the gateway opens a tunnel to the special |
16 |
>> host in the private subnet (let.s say 192.168.0.3) if there is a query |
17 |
>> for host3.domain.net? |
18 |
>> |
19 |
>> In my opinion this cannot be done because the client queries the DNS |
20 |
>> and simply opens the connection to the IP 1.2.3.4 and the gateway has |
21 |
>> now hints how to decide to which internal host the tunnel should be |
22 |
>> opened. |
23 |
>> |
24 |
>> But this setup is possible because Microsoft ISA Server exactly does |
25 |
>> this job! |
26 |
>> |
27 |
>> I have no idea how to solve this. First idea was a kernel bridge |
28 |
>> between the interfaces. |
29 |
>> |
30 |
>> Do you have any hints for me? |
31 |
>> |
32 |
>> Thanks a lot! |
33 |
>> |
34 |
>> Andreas |
35 |
>> |
36 |
> Microsoft ISA Server is a Firewall/Proxy/Reverse-Proxy ... |
37 |
> |
38 |
> So in your case, I suppose it does a reverse proxy job (not a tunneling, |
39 |
> just working as a web client for internal network). |
40 |
> |
41 |
> I already replaced several ISA server with GNU/Linux solutions, with the |
42 |
> help of Apache and his mod_proxy ... that's imho your solution. |
43 |
|
44 |
Can this also be done for SSH und IMAP stuff? |
45 |
|
46 |
> |
47 |
> -- |
48 |
> . /mRyOuNg/ . [ SoundBomb . Syn[Rj] ] . |
49 |
> |
50 |
> mail: mryoung@×××××××××.net <mailto:mryoung@×××××××××.net> |
51 |
> web : mryoung.soundbomb.net <http://mryoung.soundbomb.net/> |
52 |
|
53 |
|
54 |
-- |
55 |
gentoo-server@g.o mailing list |