Re: NAT Firewalls and Client IPs in SSL Requests

2012-01-16 Thread Sam Vaughan
On 14/01/2012, at 12:29 AM, Stuart Henderson wrote: > On 2012-01-12, Sam Vaughan wrote: >> I have a web server handling predominantly https traffic sitting on a DMZ >> behind a CARP'd firewall of two ALIX 2D3s. >> >> Since the firewall is NATting traffic to the web server, the source IP of >> req

Re: NAT Firewalls and Client IPs in SSL Requests

2012-01-13 Thread Stuart Henderson
On 2012-01-12, Sam Vaughan wrote: > I have a web server handling predominantly https traffic sitting on a DMZ > behind a CARP'd firewall of two ALIX 2D3s. > > Since the firewall is NATting traffic to the web server, the source IP of > requests arriving at the web server is always the firewall's CA