Hm, I've posted this last week, but got no response. Did nobody out on 
this list notive such behaviour?

Regards,

Joerg


------------- Begin Forwarded Message -------------

Date: Thu, 27 Jul 2000 18:02:09 +0200 (MET DST)
From: Joerg Oertel <[EMAIL PROTECTED]>
Subject: [FW1] HTTP security server: Transparent mode vs. Proxy mode
To: [EMAIL PROTECTED]
Content-MD5: /rq+I5PhctCS9Qet5W1CIg==


Hello all,

I have a question about the different modes of the HTTP security 
server.
After reading the manuals my understanding is, that in proxy mode, the 
client 
needs to have the firewall configered as proxy. In transparent mode 
the clients 
don't need to have a proxy configured, because the firewall catches 
the HTTP 
traffic and sends out the HTTP request on behalf of the client. 

Assumed my understanding is correct, a rule

client    any   http->URI-resource  accept

with the HTTP security server running in transparent mode should allow 
HTTP 
connections from the client (with no-proxy config) to any site, but 
still keeps 
it's finger on it for content checking (eg virus scan).

OTHO the rule

client    firewall   http->URI-resource   accept

with the HTTP security server running in proxy mode should allow HTTP 
access 
only to clients which have the firewall explicitly configured as 
proxy.

Assumed I'm still right, why does the second case not work? When I 
configure the 
HTTP security server to allow both modes, transparent and proxy, 
clients 
configured to use the firewall as proxy will work.

Can someone explain me where I'm wrong?

Kind regards,

Joerg 

// pallas  GmbH  ............  Joerg Oertel  ...........
   Hermuelheimer Str. 10       System engineer                   
   D-50321 Bruehl, Germany     [EMAIL PROTECTED]           
                               phone  +49-(0)2232-1896-0 
   http://www.pallas.de        fax   +49-(0)2232-1896-29
........................................................



======================================================================
==========
     To unsubscribe from this mailing list, please see the 
instructions at
               http://www.checkpoint.com/services/mailing.html
======================================================================
==========

------------- End Forwarded Message -------------


// pallas  GmbH  ............  Joerg Oertel  ...........
   Hermuelheimer Str. 10       System engineer                   
   D-50321 Bruehl, Germany     [EMAIL PROTECTED]           
                               phone  +49-(0)2232-1896-0 
   http://www.pallas.de        fax   +49-(0)2232-1896-29
........................................................



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to