Re: UPDATE: [wcolburnat_private: SMTP relay through checkpoint firewall]

From: Randal L. Schwartz (merlynat_private)
Date: Thu Feb 21 2002 - 05:50:40 PST

  • Next message: Jamie Oulman: "Re: Why is Microsoft watching us watch DVD movies?"

    >>>>> "Mike" == Mike Benham <moxieat_private> writes:
    
    Mike> People use the CONNECT method from inside a LAN to make SSL/HTTPS
    Mike> connections through a proxy.  I think it makes sense for proxies to
    Mike> support the method by default, since browsing secure pages is very
    Mike> common, but it shouldn't be accessable from outside the LAN.
    
    Out of the box, Apache-based mod_proxy servers permit CONNECT to port
    443 and 563 *only*, but can add additional ports or deny even those
    ports.  In my limited experience, almost *all* other firewall proxy
    servers I've encountered seem to permit any-host/any-port from inside,
    either through a bad default configuration, or perhaps bungling by the
    admins.  Kudos to Apache for getting it right again.
    
    -- 
    Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
    <merlynat_private> <URL:http://www.stonehenge.com/merlyn/>
    Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
    See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!
    



    This archive was generated by hypermail 2b30 : Thu Feb 21 2002 - 17:20:17 PST