Re: Q: reflector/rdr on same interface?

This is a discussion on Re: Q: reflector/rdr on same interface? within the IPFilter forums, part of the System Security and Security Related category; Nardmann, Heiko wrote: > Hi, > > in the documentation it is stated that I cannot use rdr as a ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-14-2005
Chris Ross
 
Posts: n/a
Default Re: Q: reflector/rdr on same interface?

Nardmann, Heiko wrote:
> Hi,
>
> in the documentation it is stated that I cannot use rdr as a reflector, i.e.
> if both in and out traffic go through the same interface. Now I wonder how
> solve the following situation.
>
> I have a client application where I configure ip addresses of servers to
> contact. Problem is that the customer wants SSL and the application is not
> SSL-aware. So I want to use stunnel on the same machine for tunneling. But
> how do I now redirect the application requests (to the target ips) to my
> local stunnel ports. Based on the routing both application requests and final
> stunnel requests go via the same interface. I tried to use logical interfaces
> to fool ipf but ipnat does not accept "bge0:1" (btw: Solaris 8/9 is the
> environment for this).
>
> I have thought of configuring loopback (127.x.x.x) addresses inside the
> application and redirecting these to the stunnel service ports; this might
> work (not yet tested) but is really ugly ...
>
> Maybe someone has done something similar before ... ?


I would redirect to local address on lo0. If ipf lets you get
to lo0, I know solaris' loopback is a little odd compared to
other operating systems.

I do something like this at home for transparent web caching,
using ipf 4.x on NetBSD.

- Chris
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:51 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0