Re: Need recomendations for https proxy that serves as a firewall proxy - THANX

2004-01-01 Thread Haim Ashkenazi
thanx everybody for your input. you gave me some good ideas. Bye -- Haim

Re: Need recomendations for https proxy that serves as a firewall proxy

2004-01-01 Thread ajm
Hi!! I really understand your problem. Sometimes we HAVE TO do what we wouldn't never even think about... so, the best is to try to find the best solution!! In this particular case, my response was: twhttpd. No vulnerabilities found (until now...), very well programmed, well documented, very cust

Re: Need recomendations for https proxy that serves as a firewall proxy - THANX

2004-01-01 Thread Haim Ashkenazi
thanx everybody for your input. you gave me some good ideas. Bye -- Haim -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Need recomendations for https proxy that serves as a firewall proxy

2004-01-01 Thread ajm
Hi!! I really understand your problem. Sometimes we HAVE TO do what we wouldn't never even think about... so, the best is to try to find the best solution!! In this particular case, my response was: twhttpd. No vulnerabilities found (until now...), very well programmed, well documented, very cust

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Murray J. Brown
On Wed, 2003-12-31 at 13:17, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > However, for virtual hosting across multiple back-end machines with > > authentication at the firewall, I found apache2 + mod_ssl + mod_proxy > > more suitable. Moreover, pound does not provide cachi

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > However, for virtual hosting across multiple back-end machines with > authentication at the firewall, I found apache2 + mod_ssl + mod_proxy > more suitable. Moreover, pound does not provide caching for > acceleration, nor ssl on the back channel. The que

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > How about Apache with mod_security [1]? Looks pretty good to me. Cant speak about the module, thanks for the hint. Personally I think Apache is too bloated to be used on a bastion gateway. Greetings Bernd -- eckes privat - http://www.eckes.org/ Project

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Murray J. Brown
On Wed, 2003-12-31 at 13:17, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > However, for virtual hosting across multiple back-end machines with > > authentication at the firewall, I found apache2 + mod_ssl + mod_proxy > > more suitable. Moreover, pound does not provide cachi

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > However, for virtual hosting across multiple back-end machines with > authentication at the firewall, I found apache2 + mod_ssl + mod_proxy > more suitable. Moreover, pound does not provide caching for > acceleration, nor ssl on the back channel. The que

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > How about Apache with mod_security [1]? Looks pretty good to me. Cant speak about the module, thanks for the hint. Personally I think Apache is too bloated to be used on a bastion gateway. Greetings Bernd -- eckes privat - http://www.eckes.org/ Project

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Murray J. Brown
On Wed, 2003-12-31 at 11:01, Bernd Eckenfels wrote: [...] > Unfortunatelly there are not much free HTTP Application Level Gateways > (reverse > proxies) out there which do good filtering. (And I am not sure if there are > non-free > which are good, either:). Some are listed on: > > http://www

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Chad Maine
On Wed, 2003-12-31 at 07:15, Haim Ashkenazi wrote: > Dale Amon wrote: > > > On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: > >> On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > >> > I have a client that have an exchange server inside the LAN and he > >> > wants t

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Murray J. Brown
On Wed, 2003-12-31 at 11:01, Bernd Eckenfels wrote: [...] > Unfortunatelly there are not much free HTTP Application Level Gateways (reverse > proxies) out there which do good filtering. (And I am not sure if there are non-free > which are good, either:). Some are listed on: > > http://www.freef

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Javier Fernández-Sanguino Peña
On Wed, Dec 31, 2003 at 05:01:44PM +0100, Bernd Eckenfels wrote: > > Unfortunatelly there are not much free HTTP Application Level Gateways > (reverse > proxies) out there which do good filtering. (And I am not sure if there are > non-free > which are good, either:). Some are listed on: How a

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > Maybe have a look at sslwrap+redir, or stunnel, which can run on any > machine in your DMZ and forward incoming connections to the internal > machine, adding SSL encryption to make it more secure. There is no need to add SSL encryption, IIS can do that

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Chad Maine
On Wed, 2003-12-31 at 07:15, Haim Ashkenazi wrote: > Dale Amon wrote: > > > On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: > >> On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > >> > I have a client that have an exchange server inside the LAN and he > >> > wants t

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Javier Fernández-Sanguino Peña
On Wed, Dec 31, 2003 at 05:01:44PM +0100, Bernd Eckenfels wrote: > > Unfortunatelly there are not much free HTTP Application Level Gateways (reverse > proxies) out there which do good filtering. (And I am not sure if there are non-free > which are good, either:). Some are listed on: How about A

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > Maybe have a look at sslwrap+redir, or stunnel, which can run on any > machine in your DMZ and forward incoming connections to the internal > machine, adding SSL encryption to make it more secure. There is no need to add SSL encryption, IIS can do that

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Haim Ashkenazi
Dale Amon wrote: > On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: >> On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: >> > I have a client that have an exchange server inside the LAN and he >> > wants to access the web interface from the world. I thought I'll put a

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Dale Amon
On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: > On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > > I have a client that have an exchange server inside the LAN and he wants to > > access the web interface from the world. I thought I'll put a transparent > > proxy

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Haim Ashkenazi
Dale Amon wrote: > On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: >> On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: >> > I have a client that have an exchange server inside the LAN and he >> > wants to access the web interface from the world. I thought I'll put a

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Richard Atterer
On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > I have a client that have an exchange server inside the LAN and he wants to > access the web interface from the world. I thought I'll put a transparent > proxy server on the DMZ. apt-cache search proxy gave a few options but > except

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Dale Amon
On Wed, Dec 31, 2003 at 03:05:43PM +0100, Richard Atterer wrote: > On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > > I have a client that have an exchange server inside the LAN and he wants to > > access the web interface from the world. I thought I'll put a transparent > > proxy

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Richard Atterer
On Wed, Dec 31, 2003 at 11:33:02AM +0200, Haim Ashkenazi wrote: > I have a client that have an exchange server inside the LAN and he wants to > access the web interface from the world. I thought I'll put a transparent > proxy server on the DMZ. apt-cache search proxy gave a few options but > except

Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Haim Ashkenazi
Hi I have a client that have an exchange server inside the LAN and he wants to access the web interface from the world. I thought I'll put a transparent proxy server on the DMZ. apt-cache search proxy gave a few options but except squid (which is a little overkill for this) I don't know any of the

Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Haim Ashkenazi
Hi I have a client that have an exchange server inside the LAN and he wants to access the web interface from the world. I thought I'll put a transparent proxy server on the DMZ. apt-cache search proxy gave a few options but except squid (which is a little overkill for this) I don't know any of the