Firewall / Reverse Proxy Config Questions.

Firewall / Reverse Proxy Config Questions.

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Firewall / Reverse Proxy Config Questions. Serpico 03-16-2006
Posted by Serpico on March 16, 2006, 9:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am putting together a proxy/firewall config ... and I want to pass
this by the pros to make sure I have this correct (this is my first
shot at something like this) ... and for suggestions/answers.

1: Proxy: Windows 2003 Web Edition running Apache 2.0 will act as a
reverse proxy with 2 IP's (NIC1 with 2 IPs assigned via IP aliasing) in
front of the FW.
2: Checkpoint Firewall.
3: 2 Windows 2003 Web Edition HTTP servers behind the FW

Two domains with SSL Certs will be hosted on the proxy in the DMZ:
NIC1 is connected to the ISP
https://one.somedomain.com (PUBLIC IP1:443 on Proxy NIC1)
https://two.somedomain.com (PUBLIC IP2:443 on Proxy NIC1)
NIC2 is connected to the FireWall DMZ NIC

So:

PUBLIC IP1:443 (https://one.somedomain.com) on Proxy --> FireWall Port
5000 --> INTERNAL IP1:80
PUBLIC IP2:443 (https://two.somedomain.com) on Proxy --> FireWall Port
5001 --> INTERNAL IP2:80

Site "One":
Proxy will fwd requests from "one:443" to "Firewall IP Port 5000".
Firewall will fwd requests from "Firewall IP Port 5000" to "Internal
IP1:80".

Site "Two":
Proxy will fwd requests from "two:443" to "Firewall IP Port 5001".
Firewall will fwd requests from "Firewall IP Port 5001" to "Internal
IP2:80".

Three Question:
1: Does this look correct? Any errors?Am I close?
2: Do I need to setup some sort of routing on the Proxy to route
traffic from NIC1 to NIC2?
3: I am not sure how the IP's should be config'd between the proxy and
the FW:

Proxy NIC 1 is easy since that is obviously the ISP IP config, and the
internal net I can make whatever I need it to be. So what would the
IP/Gateway/Netmask config be for Proxy NIC2 and the FW DMZ NIC?

Thanks.


Similar ThreadsPosted
Reverse DNS May 1, 2005, 7:42 pm
Reverse HTTPS Tunnel??? February 8, 2005, 7:43 am
Web Application Firewalls / Reverse Proxies? January 30, 2007, 4:20 am
Commercial Web Application Firewalls or Reverse Proxies? October 22, 2005, 8:06 pm
firewall config April 15, 2008, 7:17 pm
config ipcop firewall December 18, 2005, 5:50 am
PIX DMZ Config help November 5, 2007, 1:07 pm
Netscreen 5GT config February 27, 2005, 2:56 am
Cisco Pix 506 config March 31, 2005, 10:00 am
Kerio Config June 29, 2006, 8:13 am

The site map in XML format XML site map

Contact Us | Privacy Policy