Gentoo Archives: gentoo-server

From: Andreas Herrmann <sma@××××××××××××××××.de>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Routing into private subnet
Date: Fri, 18 Aug 2006 16:47:17
Message-Id: 44E5EE38.8040407@physik.tu-berlin.de
In Reply to: Re: [gentoo-server] Routing into private subnet by mRyOuNg
1 mRyOuNg schrieb:
2 > Andreas Herrmann wrote:
3 >> Hi there,
4 >>
5 >> I want to setup a gateway / firewall solution with Gentoo. The network
6 >> has following structure:
7 >>
8 >> Several host (host[1,...,x].domain.net) are defined within the DNS and
9 >> all of them have the same A-Record with the IP 1.2.3.4
10 >> The gateway is listening on its external network interface with the IP
11 >> 1.2.3.4 and has an internal interface with a private subnet
12 >> (192.168.0.0/24). The hosts (host[1,...,x].) are addressed in this
13 >> subnet.
14 >>
15 >> How can it be solved, that the gateway opens a tunnel to the special
16 >> host in the private subnet (let.s say 192.168.0.3) if there is a query
17 >> for host3.domain.net?
18 >>
19 >> In my opinion this cannot be done because the client queries the DNS
20 >> and simply opens the connection to the IP 1.2.3.4 and the gateway has
21 >> now hints how to decide to which internal host the tunnel should be
22 >> opened.
23 >>
24 >> But this setup is possible because Microsoft ISA Server exactly does
25 >> this job!
26 >>
27 >> I have no idea how to solve this. First idea was a kernel bridge
28 >> between the interfaces.
29 >>
30 >> Do you have any hints for me?
31 >>
32 >> Thanks a lot!
33 >>
34 >> Andreas
35 >>
36 > Microsoft ISA Server is a Firewall/Proxy/Reverse-Proxy ...
37 >
38 > So in your case, I suppose it does a reverse proxy job (not a tunneling,
39 > just working as a web client for internal network).
40 >
41 > I already replaced several ISA server with GNU/Linux solutions, with the
42 > help of Apache and his mod_proxy ... that's imho your solution.
43
44 Can this also be done for SSH und IMAP stuff?
45
46 >
47 > --
48 > . /mRyOuNg/ . [ SoundBomb . Syn[Rj] ] .
49 >
50 > mail: mryoung@×××××××××.net <mailto:mryoung@×××××××××.net>
51 > web : mryoung.soundbomb.net <http://mryoung.soundbomb.net/>
52
53
54 --
55 gentoo-server@g.o mailing list

Replies

Subject Author
Re: [gentoo-server] Routing into private subnet Jeroen Geilman <jeroen@××××××.nl>
Re: [gentoo-server] Routing into private subnet mRyOuNg <mryoung@×××××××××.net>