NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] Proxy for https



Hello,

recently I was playing with the ahttpd and it's https support. I found a neat 
thing.

I have a rule that allows the clients to use the ahttpd as proxy.

clients    fw1     http-proxy->URI-ressource   user-auth

When I configure the client's browser to use fw1 as proxy for http and ftp, this 
works great. Configuring the browser to use fw1 as proxy for https doesn't work.
So I added a rule

clients    any     https    allow

to allow direct the clients direct access to https-servers.
Well, when I configure to use no proxy for https, I can acces the https-servers. 
The FW-1-log shows that I use the special https rule. When I configure the 
browser to use fw1 as proxy also for https, guess what, it works too. The 
FW-1-log still shows that the client uses the https rule rather than the first 
one. But a snoop shows that the client is only communicating with the 
ahttpd-proxy on fw1.

Can anybody explain what's going on here?

Kind regards,

Jörg

PS. It's FW-1 4.1 SP2 on a Sun E250 dual CPU with Solaris 2.7




// pallas  GmbH  ............  Joerg Oertel  ...........
   Hermuelheimer Str. 10       System engineer                   
   D-50321 Bruehl, Germany     [email protected]           
                               phone  +49-(0)2232-1896-0 
   http://www.pallas.de        fax   +49-(0)2232-1896-29
........................................................



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.