[stunnel-users] Choosing local 'source' IP?

This is a discussion on [stunnel-users] Choosing local 'source' IP? within the Stunnel Users forums, part of the Networking and Network Related category; Ok, so here's the problem: I've got stunnel handling SSL for a web-based service that is otherwise ...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-17-2006
Don Werve
 
Posts: n/a
Default [stunnel-users] Choosing local 'source' IP?

Ok, so here's the problem: I've got stunnel handling SSL for a web-based
service that is otherwise too stupid to be able to talk https.
Unfortunately, I need to set up a redirection rule inside this service
that bounces people back to the https:// page if they try to come in
over http. Since said service isn't managing its own SSL, I have no
solid way of determining which connections are wrappered by stunnel and
which connections come in over the wire, and if I bounce stunnel
connections, I end up in an infinite loop.

Fortunately, all stunnel connections give a REMOTE_IP of the second
ethernet adapter of the host system, which is good. My question is, how
do I configure stunnel to 'force' this behavior? E.g., I want to
explicitly specify in stunnel.conf 'Connect to the service for which you
are acting as a wrapper from *this* IP/interface'.

I've tried the 'local = ' option and setting socket flags for 'l' and
'r', and while they don't break anything, I can't use them to force a
connection from any other adapter, so I don't think they are doing what
I need. This wouldn't be an issue, either, except I don't know how
stunnel determines this, and I don't want to (at some point in the
future) have things 'magically change' (read: break horribly).

Thanks-in-advance!

--
Don Werve <donw@iradeon.net>
Chief Systems Administrator / Systems Architect
_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 02:19 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0